Amazon Bedrock's ServiceNow connector may bypass document access restrictions
A pilot implementation of Amazon Bedrock's ServiceNow connector revealed potential security implications. The documentation instructs administrators to assign roles that bypass per-knowledge-base user criteria restrictions. During testing on September 4, 2026, a service account configured exactly as documented successfully retrieved documents restricted to specific user groups. This allowed an internal IT assistant to return sensitive information to unauthorized users during a staging environment test. The configuration followed AWS guidelines precisely, highlighting the described system behavior.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in