Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    This Week’s Awesome Tech Stories From Around the Web (Through August 1)

    August 1, 2026

    Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal

    August 1, 2026

    The Man Who Understood Risk: Robert N. Charette retires.

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    • This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence
    • Europe Approves Bionic Eye to Restore Vision Lost to Blindness
    • Chinese AI Researchers Are Finding Their Voice on X
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Snowpick: Open-source ServiceNow exposure scanner
    Cybersecurity

    Snowpick: Open-source ServiceNow exposure scanner

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 22, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Snowpick: Open-source ServiceNow exposure scanner
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back.

    Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests. The firm published the results along with the Go tool it used, Snowpick.

    Findings came back from 31% of the instances. Those instances returned records or confirmed record counts to a session carrying no credentials, and they traced to roughly three-quarters of the organizations in the dataset.

    “The row-returning exposures we confirmed were not new zero-days. They were access-control and configuration issues across public ServiceNow surfaces,” Emilio Gallegos, the adversarial operator at Bishop Fox who wrote the tool, told Help Net Security.

    Two surfaces, two sets of rules

    ServiceNow hands out data through Service Portal widgets and through the Table REST API. Widgets live at /api/now/sp/widget/{widget_id}, accept POST requests, and drive knowledge base search, catalog pages, ticket forms, and attachment views. The Table REST API at /api/now/table/{table_name} queries sys_user, incident, oauth_entity, and the rest of the schema directly.

    Each surface evaluates access control on its own path. An instance can lock its widgets down and keep answering table queries. Two instances in the dataset did that: widget probes came back clean, and the REST API returned data.

    The attachment widget did most of the work

    Most positive findings arrived through ticket-attachments, a stock widget that returns metadata about files attached to tickets. Titles and descriptions in that metadata carry internal process detail: onboarding guides, access request procedures, system how-tos.

    Exposed knowledge base articles, incident ticket metadata, service catalog items, department structures, and facility locations turned up across the set. Record counts per finding ran from dozens into the thousands.

    Credentials stayed out of this sample. The same surfaces reach oauth_entity and sys_user when ACLs permit it.

    What the tool does

    Snowpick requests the public login page, extracts the session token ServiceNow issues there, and reuses it for follow-on API calls. It probes a set of default widgets plus 26 built-in table and field pairs, and it can ask the instance which widgets are installed and add those to the list.

    Custom widgets earn that discovery step. Organizations write their own access rules for them, and those rules never passed through platform review.

    The output separates row exposure from a count oracle, meaning ServiceNow confirmed that matching records exist and returned none of them. Varonis Threat Labs documented blind inference through count behavior, tracked as CVE-2025-3648. For each finding Snowpick saves the reported total, a bounded sample of rows, and a curl command that reproduces the request.

    Publishing a tool that cuts both ways

    Anyone can point Snowpick at an instance they do not own. Gallegos said his team started from that. “The question we focused on was whether release would materially change attacker capability or improve defender visibility.”

    The underlying techniques were public already. Aaron Costello documented widget-simple-list exposure in October 2023, including session token bootstrapping and table enumeration, and AppOmni followed with analysis of ServiceNow ACL mechanics.

    Gallegos put the release decision this way: “We published Snowpick because keeping it internal would not slow anyone probing systems they don’t own – it would only keep the people accountable for these systems from finding and fixing that exposure before it becomes an incident.”

    Fixing it

    Platform defaults can carry part of the load. Gallegos said guardrails around public widgets and table access raise the floor, and that ServiceNow is built to be customized. “Organizations add their own widgets, tables, roles, and ACLs over time, and those combinations can behave differently than expected when reached from an unauthenticated session.”

    “This is shared responsibility. ServiceNow can reduce the number of unsafe patterns, but customers still need to test their own public-facing instances from the outside, the way an attacker would.”

    Remediation work starts with public Service Portal widgets that return ticket, attachment, knowledge base, catalog, or list data. Table-level, field-level, and row-level ACLs need a separate pass. A widget blocked on direct load can still be reachable through another widget that loads it.

    Snowpick is available for free on GitHub.

    Must read:

    Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!

    Exposure opensource scanner ServiceNow Snowpick
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World

    This Week’s Awesome Tech Stories From Around the Web (Through August 1)

    August 1, 2026

    Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal

    August 1, 2026

    The Man Who Understood Risk: Robert N. Charette retires.

    August 1, 2026

    7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

    August 1, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.