Cloud technology giant ServiceNow has notified some of its customers that a software bug on its platform was allowing anyone on the internet to access their data. According to a report in TechCrunch, a knowledge base article, which ServiceNow has hidden behind a login wall but has been shared on Reddit, says that the company on June 5 patched some customer instances to fix a bug that had allowed unauthenticated users to “gain greater access” to ServiceNow-hosted data than intended.

ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from…

A ServiceNow security issue allowed unauthenticated users, in certain circumstances, to gain greater access to susceptible instances than intended.