logo

ServiceNow patches critical AI platform flaw that could allow user impersonation

ID: 931241b5-2c52-5b3e-9c70-50766a552990

STIX ID: report--931241b5-2c52-5b3e-9c70-50766a552990

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Greg Otto

...
...

ServiceNow patched a critical vulnerability (CVE-2025-12420, CVSS 9.3) affecting Now Assist AI Agents and the Virtual Agent API that could allow unauthenticated user impersonation and unauthorized actions; AppOmni discovered the flaw and fixes were deployed to most hosted instances on Oct 30, 2025 with patches provided to partners and self-hosted customers. The accompanying research also revealed that default agent-discovery settings can enable second-order prompt-injection attacks where low-privileged data fields are later processed by higher-privileged AI agents, enabling data access/modification and potential privilege escalation; ServiceNow has updated documentation and recommends mitigations such as agent segmentation, human supervision for powerful agents, and monitoring agent behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.