BodySnatcher – New Vulnerability Allows Attacker to Impersonate Any ServiceNow User
ID: e5a50d30-1ee5-5382-971b-22934b1790a3
STIX ID: report--e5a50d30-1ee5-5382-971b-22934b1790a3
Feed Name: cybersecurityNews.com
**Summary:** A critical vulnerability (CVE-2025-12420) in ServiceNow’s Now Assist AI Agents and Virtual Agent API allows remote unauthenticated attackers to impersonate users, bypass MFA/SSO using a universal hardcoded authentication token and insecure account-linking, and create privileged accounts; ServiceNow released patches and rotated provider credentials on Oct 30, 2025, and administrators are advised to update to fixed versions, enforce MFA for account-linking, and audit/deactivate unused AI agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
