CVE-2025-3648Disclosure

LOWCVSS 8.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and authenticated users to use range query requests to infer instance data that is not intended to be accessible to them. To assist customers in enhancing access controls, ServiceNow has introduced additional access control frameworks in Xanadu and Yokohama, such as Query ACLs, Security Data Filters and Deny-Unless ACLs. Additionally, in May 2025, ServiceNow delivered to customers a security update that is designed to enhance customer ACL configurations. Customers, please review the KB Articles in the References section.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1220

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-13: 1Mentions · 2026-07-15: 1Mentions · 2026-10-07: 1Active Exploitation · 2026-07-15: 1Technical Details · 2026-02-13: 1Technical Details · 2026-07-15: 102-1307-1510-07
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-131
Disclosure1
2026-07-151
Active Exploitation1
Full discourse3 posts
  • DailyCVE@dailycve

    🟠 ServiceNow, Misconfigured Access Control List (ACL), #CVE-2025-3648 (Medium) -DC-Oct2026-2805 https://dailycve.com/servicenow-misconfigured-access-control-list-acl-cve-2025-3648-medium-dc-oct2026-2805/

    0000025
    239 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited ServiceNow's misconfigured REST API (CVE-2025-3648) to access customer data without authentication, then escalated privileges and moved laterally within cloud environments. Runtime segmentation could have limited the blast radius of this breach chain. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/servicenow-unauthenticated-api-data-exposure-june-2026

    Post summary

    Attackers leveraged CVE-2025-3648 in ServiceNow to gain unauthenticated access, escalating privileges and moving laterally, indicating active exploitation in the wild. No patch, PoC, or exploit code details are provided in the text.

    0000045
    1.9K followersView on X
  • @pedri77@pedri77
    Disclosure

    A high-severity security flaw has been disclosed in ServiceNow's platform that, if successfully exploited, could result in data exposure and exfiltration. The vulnerability, tracked as CVE-2025-3648 (CVSS score: 8.2... https://f.mtr.cool/dzvoxnabyb

    Post summary

    A high‑severity vulnerability (CVE‑2025‑3648) has been disclosed in ServiceNow’s platform, with a CVSS score of 8.2 and the potential for data exposure and exfiltration.

    0000048
    2.1K followersView on X

Explore more