ServiceNow CVE-2025-3648
ServiceNow Access Control Flaw
Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.
Risk & exploitation
EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and authenticated users to use range query requests to infer instance data that is not intended to be accessible to them.
To assist customers in enhancing access controls, ServiceNow has introduced additional access control frameworks in Xanadu and Yokohama, such as Query ACLs, Security Data Filters and Deny-Unless ACLs.
Additionally, in May 2025, ServiceNow delivered to customers a security update that is designed to enhance customer ACL configurations.
Customers, please review the KB Articles in the References section.
Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| All supported releases | see advisory — release families not published in NVD |
Source & attribution
GHSA GHSA-f77v-7fv6-253h + NVD https://nvd.nist.gov/vuln/detail/CVE-2025-3648 (auto-synced 2026-06-08); CVSS/CWE/KEV/references from the GitHub Advisory Database (CC-BY 4.0). GHSA carries no version data — per-release fixed-in is the NVD-CPE hint or TODO: verify on the login-gated support.servicenow.com KB.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(i)
- DORA Art.9§1
- DORA Art.9§4(c)
- DORA RTS Art.10
- DORA RTS Art.21
- ISO A.8.3
- ISO A.8.9
- GDPR Art.32§1(b)
Decision support, not a reporting determination.
References
- https://github.com/advisories/GHSA-f77v-7fv6-253h
- https://nvd.nist.gov/vuln/detail/CVE-2025-3648
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2046494
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2139567
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2256712
- https://www.cve.org/CVERecord?id=CVE-2025-3648
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.