logo

AppOmni Surfaces BodySnatcher AI Agent Security Flaw Affecting ServiceNow Apps

ID: 15cc0ca3-3b2a-5e37-98dc-c9ad2c164fbd

STIX ID: report--15cc0ca3-3b2a-5e37-98dc-c9ad2c164fbd

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Michael Vizard

...
...

AppOmni disclosed a ServiceNow vulnerability called “BodySnatcher” (CVE-2025-12420) that permitted unauthenticated user impersonation using only an email address, bypassing MFA and SSO and enabling creation of privileged AI agents via the Virtual Agent API; ServiceNow has issued a patch and there are no reported active exploitations, while researchers warn of high blast radius risks from compromised AI agents and urge stronger controls and preparedness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.