PYSEC-2026-1690
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
Quick fix
PYSEC-2026-1690 — nautobot-ssot: upgrade to the fixed version with the command below.
pip install --upgrade 'nautobot-ssot>=3.10.0'Details
The servicenow config URL is using a generic django View with no authentication.
URL: `/plugins/ssot/servicenow/config/`
### Impact _What kind of vulnerability is it? Who is impacted?_ An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. `companyname.service-now.com`. This is considered **low-value information**. This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain access to other pages Nautobot through the unauthenticated Configuration page.
### Patches _Has the problem been patched? What versions should users upgrade to?_ We highly recommend upgrading to SSoT v3.10.0 which includes this patch.
### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ Disable the servicenow SSoT integration
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/nautobot/nautobot-app-ssot/security/advisories/GHSA-535g-62r7-cx6v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-62607[ADVISORY]
- https://github.com/nautobot/nautobot-app-ssot/commit/1530d25cdeb929641ec47644f9a0a1d9d41e1cb8[WEB]
- https://github.com/nautobot/nautobot-app-ssot[PACKAGE]
- https://github.com/nautobot/nautobot-app-ssot/releases/tag/v3.10.0[WEB]
- https://pypi.org/project/nautobot-ssot[PACKAGE]
- https://github.com/advisories/GHSA-535g-62r7-cx6v[ADVISORY]