logo

New “BodySnatcher” Flaw Allows Full ServiceNow User Impersonation

ID: 1ef53e48-2fb2-5369-be5f-b76c76747ddd

STIX ID: report--1ef53e48-2fb2-5369-be5f-b76c76747ddd

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Divya

...
...

A security researcher disclosed a critical vulnerability dubbed 'BodySnatcher' (CVE-2025-12420) affecting ServiceNow's Virtual Agent API and Now Assist AI Agents on on‑premise deployments; the flaw uses a globally shared static client secret plus an email-based auto-linking mechanism to allow unauthenticated attackers to impersonate any user, bypass MFA/SSO, execute privileged AI workflows, and create backdoor administrator accounts. Proof-of-concept exploitation demonstrated account creation, privilege escalation, and full platform access; ServiceNow released patches for affected versions and customers are advised to upgrade, enforce MFA on agent linking, require approval workflows, and audit/deactivate unused AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.