logo

BodySnatcher – New Vulnerability Allows Attacker to Impersonate Any ServiceNow User

ID: e5a50d30-1ee5-5382-971b-22934b1790a3

STIX ID: report--e5a50d30-1ee5-5382-971b-22934b1790a3

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Summary:** A critical vulnerability (CVE-2025-12420) in ServiceNow’s Now Assist AI Agents and Virtual Agent API allows remote unauthenticated attackers to impersonate users, bypass MFA/SSO using a universal hardcoded authentication token and insecure account-linking, and create privileged accounts; ServiceNow released patches and rotated provider credentials on Oct 30, 2025, and administrators are advised to update to fixed versions, enforce MFA for account-linking, and audit/deactivate unused AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.