CVE-2025-12420Disclosure(servicenow / now_assist_ai_agents)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch servicenow now_assist_ai_agents systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to  hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • now_assist_ai_agents
  • virtual_agent_api

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 1 mentions (2026-02-05); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Vendors
Products
now_assist_ai_agentsvirtual_agent_api

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-02-05: 1Mentions · 2026-02-16: 1Mentions · 2026-02-17: 1Mentions · 2026-02-26: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-29: 1Active Exploitation · 2026-03-09: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 102-0502-1602-1702-2603-0903-1003-1103-29
Signal classification4 categories
Disclosure
450.0%
General
225.0%
Active Exploitation
112.5%
Patch
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-051
Disclosure1
2026-02-161
Disclosure1
2026-02-171
General1
2026-02-261
Disclosure1
2026-03-091
Active Exploitation1
2026-03-101
Disclosure1
2026-03-111
General1
2026-03-291
Patch1
Full discourse8 posts
  • Swissky@pentest_swissky
    Disclosure

    BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow - @AppOmniSecurity https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/

    Post summary

    The post announces a new ServiceNow vulnerability (CVE-2025-12420) involving broken authentication and agentic hijacking, but provides no evidence of exploitation, PoC, or patch status.

    1211071.9K
    21.1K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow http://dlvr.it/TR00jB #cyber #threathunting #infosec

    Post summary

    The post announces a broken authentication and agentic hijacking vulnerability (CVE-2025-12420) in ServiceNow, but offers no proof of concept, exploit code, or patch information.

    00011552
    54.6K followersView on X
  • StratoKey@StratoKey
    Disclosure

    The #BodySnatcher vulnerability in ServiceNow (CVE-2025-12420) shows how weak #APIauthentication and identity linking can be abused via #agentic #AI workflows. Read our latest article: ServiceNow BodySnatcher Vulnerability Exposes Agentic AI Security Gap https://hubs.ly/Q041Wb-00 https://t.co/5DWniF469S

    Post summary

    An article announces ServiceNow CVE‑2025‑12420, highlighting weak API authentication and identity linking vulnerabilities that can be exploited through agentic AI workflows; no PoC, exploit, or patch details are provided.

    2000082
    201 followersView on X
  • The Agent Economist@The_Agent_Econ
    Patch

    breaking: microsoft's copilot faces 2025's echoleak (cve-32711), a critical zero-click vuln. servicenow virtual agent is hit by bodysnatcher (cve-2025-12420). langflow's cve-2026-33017 is critical. your ai agents are high-value targets. audit and patch your systems now. https://t.co/p2qJ5fPUU3

    Post summary

    The tweet warns of critical zero‑click vulnerabilities affecting Microsoft Copilot, ServiceNow, and Langflow, urging immediate auditing and patching.

    00000236
    14 followersView on X
  • VulnTracker@vuln_tracker
    General

    "Agentic hijacking" in ServiceNow represents a completely new attack class we'll need to defend against. Your research into AI agent security vulnerabilities is ahead of the curve. Thanks for the detailed analysis! We've added this CVE on our dashboard, check it out: https://vulntracker.io/cves/CVE-2025-12420

    Post summary

    The post references CVE‑2025‑12420 via a dashboard link and notes a new "Agentic hijacking" attack class, but offers no proof‑of‑concept, exploit code, or mitigation details.

    0000041
    397 followersView on X
  • Rav@_MrDecentralize
    Active Exploitation

    Your customer service agent authenticated once. Now it has standing permissions to every financial record in the system. ServiceNow CVE-2025-12420 exposed this pattern at Fortune 100 scale. Virtual Agent API allowed unauthenticated admin impersonation via hardcoded platform secret. Bypassed MFA, bypassed SSO, bypassed every control that protected the integration. Design reviews saw: trusted vendor, OAuth integration, role-based permissions, encrypted transmission. Everything checked. Security team approved the deployment. Regulators see something different. They ask: "Who authorized this specific account access?" The answer is "the agent's standing permissions." Not a human decision. Not a traceable approval. An authentication event that became permanent authorization state. The audit trail shows agent activity. The accountability chain stops at a service account. One is a technical control. The other is a governance failure. SOC 2 doesn't care which one you intended.

    Post summary

    ServiceNow CVE‑2025‑12420 enabled unauthenticated admin impersonation via a hardcoded secret in the Virtual Agent API; evidence suggests this flaw has been exploited at Fortune 100 scale, bypassing MFA, SSO, and other controls. No patches or PoC details are provided.

    0000065
    4.9K followersView on X
  • Rav@_MrDecentralize
    Disclosure

    Authentication at the perimeter is not authorization inside the workflow. CVE-2025-12420 documented exactly this: platforms authenticated the agent session correctly, then performed zero per-action authorization verification on tool calls. Unauthenticated attackers impersonated users downstream because the authorization chain never existed. Multi-agent architectures delegate authority recursively. Each hop in the chain inherits the previous agent's scope: without attenuation, without runtime checks, without a boundary where privilege escalation is evaluated before the next action fires. One compromised sub-agent in a payment workflow doesn't trigger a perimeter alert. It triggers a high-value transfer. By the time the FFIEC CAT review finds the control failure, the material finding is already written. The security team sees a session authentication model. The regulatory examiner sees an authorization architecture that doesn't exist below the surface. One protects the front door. The other governs what happens after it opens.

    Post summary

    The post explains CVE‑2025‑12420 as a flaw where authentication is performed but no per‑action authorization checks exist, enabling impersonation and privilege escalation in multi‑agent workflows, but it does not mention any PoC, exploit, patch, or active exploitation.

    0000049
    5.1K followersView on X
  • Komodo Cyber Security@Komodosec
    General

    #VulnerabilityReport #AIsecurity AI Identity Theft: Critical ServiceNow Flaw (CVE-2025-12420) Allows Unauthenticated Impersonation https://securityonline.info/ai-identity-theft-critical-servicenow-flaw-cve-2025-12420-allows-unauthenticated-impersonation/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet highlights a ServiceNow flaw (CVE‑2025‑12420) that permits unauthenticated impersonation, but offers no further technical or mitigation details.

    0000085
    1.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appservicenownow_assist_ai_agents---
Appservicenowvirtual_agent_api---

Explore more