logo

ServiceNow Vulnerability Enables Privilege Escalation Without Authentication

ID: 09a08eb0-5e80-5ec8-bc53-addfbb34aa64

STIX ID: report--09a08eb0-5e80-5ec8-bc53-addfbb34aa64

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

Author: Divya

...
...

A critical privilege-escalation vulnerability (CVE-2025-12420) was found in ServiceNow’s AI Platform that can let unauthenticated attackers impersonate other users and perform unauthorized actions; AppOmni reported the flaw, ServiceNow pushed fixes to hosted instances on October 30, 2025 and provided patches for partners and self-hosted customers, and customers are urged to apply specified version upgrades immediately despite no confirmed in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.