
🟠 ServiceNow, Misconfigured Access Control List (ACL), #CVE-2025-3648 (Medium) -DC-Oct2026-2805 https://dailycve.com/servicenow-misconfigured-access-control-list-acl-cve-2025-3648-medium-dc-oct2026-2805/
Exploitation ongoing with high activity in latest observed window (1 mentions)
Recommended action window: Immediate (within 24h)
NVD description
A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and authenticated users to use range query requests to infer instance data that is not intended to be accessible to them. To assist customers in enhancing access controls, ServiceNow has introduced additional access control frameworks in Xanadu and Yokohama, such as Query ACLs, Security Data Filters and Deny-Unless ACLs. Additionally, in May 2025, ServiceNow delivered to customers a security update that is designed to enhance customer ACL configurations. Customers, please review the KB Articles in the References section.
Priority
LOW
Exploitation
ACTIVE
PoC
NONE
Patch
NONE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-02-13 | 1 | Disclosure1 |
| 2026-07-15 | 1 | Active Exploitation1 |

🟠 ServiceNow, Misconfigured Access Control List (ACL), #CVE-2025-3648 (Medium) -DC-Oct2026-2805 https://dailycve.com/servicenow-misconfigured-access-control-list-acl-cve-2025-3648-medium-dc-oct2026-2805/

TRC analysis shows attackers exploited ServiceNow's misconfigured REST API (CVE-2025-3648) to access customer data without authentication, then escalated privileges and moved laterally within cloud environments. Runtime segmentation could have limited the blast radius of this breach chain. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/servicenow-unauthenticated-api-data-exposure-june-2026
Post summary
Attackers leveraged CVE-2025-3648 in ServiceNow to gain unauthenticated access, escalating privileges and moving laterally, indicating active exploitation in the wild. No patch, PoC, or exploit code details are provided in the text.

A high-severity security flaw has been disclosed in ServiceNow's platform that, if successfully exploited, could result in data exposure and exfiltration. The vulnerability, tracked as CVE-2025-3648 (CVSS score: 8.2... https://f.mtr.cool/dzvoxnabyb
Post summary
A high‑severity vulnerability (CVE‑2025‑3648) has been disclosed in ServiceNow’s platform, with a CVSS score of 8.2 and the potential for data exposure and exfiltration.