← All CVEs & advisories

ServiceNow KB1553688

Public Simple List Widget Data Exposure (misconfiguration)

AccessControlPriority 0Disclosed 2023-10-14Unverified

Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.

Risk & exploitation

PriorityLow · 0/100
EPSSnot published
CISA KEVNo
Public exploitNone indexed

No EPSS score is published for this advisory yet; priority uses the available signals. Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

A ServiceNow security advisory with no CVE (classed as a misconfiguration, not a platform

vulnerability). Public-facing Service Portal widgets (notably the Simple List / SimpleListWidget)

served by ACLs with no role, an empty condition, and an empty script allow an unauthenticated

actor to read records — including PII — by querying the widget directly. Publicly analysed by AppOmni

(Aaron Costello) in October 2023; ServiceNow responded by tightening OOB ACL defaults and restricting

ACLs that reference non-existent roles. The remediation is configuration, not a patch — see the

cross-linked ACL guidance (ACL-001) for the permit-all ACL pattern this exploits.

A closely related 2024 follow-up — public widgets able to read Knowledge Base articles secured by

User Criteria rather than ACLs (so UserIsAuthenticated did not apply) — is the same class of

exposure. Its distinct ServiceNow KB number is not publicly recoverable (login-gated); track it here

as related until the id is confirmed.

Affected releases & fixed-in

ReleaseFixed in
All releases (configuration-dependent)Mitigation, not a patch: restrict public ACLs (no role + empty condition + empty script). ServiceNow tightened OOB ACL defaults and restricted ACLs pointing at non-existent roles (Oct 2023).
Source & attribution

ServiceNow KB1553688 (login-gated); public technical analysis by AppOmni (Aaron Costello). This is a misconfiguration advisory with no CVE — affected scope is configuration-dependent, not version-bound.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for KB1553688

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.