logo

AI Identity Theft: Critical ServiceNow Flaw (CVE-2025-12420) Allows Unauthenticated Impersonation

ID: ab53c85e-3e43-5f7e-beb7-bbc1b5937530

STIX ID: report--ab53c85e-3e43-5f7e-beb7-bbc1b5937530

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical authentication flaw (CVE-2025-12420) was disclosed in the ServiceNow AI Platform that could permit unauthenticated attackers to impersonate other users and escalate privileges. ServiceNow released security updates for most hosted instances on October 30, 2025, and published patched versions for affected Store Applications (Now Assist AI Agents and Virtual Agent API), but self-hosted customers must apply fixes urgently; no evidence of in-the-wild exploitation was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.