Back to Research blog

A Deep Dive into Three ServiceNow Vulnerabilities

Share on social

August 8, 2024

Lorem ipsum

Table of Contents

Overview

Over the last decade, ServiceNow has been deployed readily across enterprises. With its growing popularity, combined with the lack of visibility organizations have on its security posture, at Assetnote, we worked hard to discover ServiceNow vulnerabilities.

Assetnote Security Researcher, Adam Kues, spent over a month finding an exploit chain and was credited with CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217. At the time of discovery, these vulnerabilities affected an estimated 42,000+ ServiceNow instances globally.

The exploit chain would allow attackers to do the following on any ServiceNow instance without authentication (versions Vancouver and Washington):

  • Execute arbitrary Glide scripting language code
  • Executing arbitrary commands on any connected MID servers
  • Reading local system files

We released a vulnerability check through the Assetnote platform to identify vulnerable customer instances. Customers were provided a mitigation, long before any official patches were deployed.

We reported this issue on May 14th, 2024. ServiceNow responded incredibly quickly and applied the update to all customers (excellent work!). We had the chance to work closely with their team to address these vulnerabilities, and they continued to roll out patches to secure customer instances.

Michael Gianarakis

Author

Michael Gianarakis

CEO at Searchlight Cyber

Michael Gianarakis is CEO of Searchlight Cyber, a leader in premptive cybersecurity. With over a decade in the security industry, Michael has built and led offensive security teams across Asia Pacific and Japan. In 2018 he co-founded Assetnote, a pioneering attack surface management platform acquired by Searchlight Cyber in 2025 – bringing best-in-class ASM capability into the PTEM platform. Michael is a respected security researcher and has presented at DEF CON, Black Hat Asia, BSides Las Vegas, Hack in the Box, AusCERT, Thotcon, 44Con, and OWASP.

Shubham Shah

Author

Shubham Shah

Chief Security Research Officer at Searchlight Cyber

Shubham Shah is Chief Security Research Officer, having joined Searchlight Cyber following the acquisition of Assetnote, where he was Co-Founder and CTO. Shubham leads the global security research team whose findings feed directly into Searchlight Exposure – surfacing zero-day vulnerabilities in the tools organisations rely on, often months ahead of public disclosure. He remains a prolific bug bounty hunter ranked in the top 50 hackers on HackerOne, and has presented at various industry events including QCon London, Kiwicon, AusCert, BSides Canberra, and CrikeyCon.

Adam Kues

Author

Adam Kues

Security Researcher at Searchlight Cyber

Explore related Content

Research

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

July 20, 2026

Research

wp2shell: Pre Authentication RCE in WordPress Core

July 17, 2026

Research

Smashing the ServiceNow Sandbox – Pre Authentication RCE

July 14, 2026

Research

CargoWise WebTracker – The Keys Were in the Cargo

June 25, 2026

Research

Two Bypasses for Chrome's Sanitizer API

May 22, 2026

Research

Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)

May 21, 2026