ServiceNow Vulnerability Enables Privilege Escalation Without Authentication
ID: 09a08eb0-5e80-5ec8-bc53-addfbb34aa64
STIX ID: report--09a08eb0-5e80-5ec8-bc53-addfbb34aa64
Feed Name: GBHackers
Threat Score
A critical privilege-escalation vulnerability (CVE-2025-12420) was found in ServiceNow’s AI Platform that can let unauthenticated attackers impersonate other users and perform unauthorized actions; AppOmni reported the flaw, ServiceNow pushed fixes to hosted instances on October 30, 2025 and provided patches for partners and self-hosted customers, and customers are urged to apply specified version upgrades immediately despite no confirmed in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
