AI Identity Theft: Critical ServiceNow Flaw (CVE-2025-12420) Allows Unauthenticated Impersonation
ID: ab53c85e-3e43-5f7e-beb7-bbc1b5937530
STIX ID: report--ab53c85e-3e43-5f7e-beb7-bbc1b5937530
Feed Name: securityonline.info
A critical authentication flaw (CVE-2025-12420) was disclosed in the ServiceNow AI Platform that could permit unauthenticated attackers to impersonate other users and escalate privileges. ServiceNow released security updates for most hosted instances on October 30, 2025, and published patched versions for affected Store Applications (Now Assist AI Agents and Virtual Agent API), but self-hosted customers must apply fixes urgently; no evidence of in-the-wild exploitation was reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
