Concern about the service -Netherow Failure could let the hackers steal private table data


  • An accident in the ServiceNow access control lists meant that users could be granted access, without fulfilling all the conditions
  • New checks have been added to mitigate the risk
  • Users are advised to examine their tables and ACL

A flaw in ServiceNow could have allowed the actors to threaten to exfiltrate sensitive data from other users without them never knowing, warned security experts.

The defect, followed like CVE-2025-3648 and gave a gravity score of 8.2 / 10 (high), was nicknamed “Count (ER) Strike” and was spotted by Varonis security researchers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top