AppOmni Surfaces BodySnatcher AI Agent Security Flaw Affecting ServiceNow Apps
ID: 15cc0ca3-3b2a-5e37-98dc-c9ad2c164fbd
STIX ID: report--15cc0ca3-3b2a-5e37-98dc-c9ad2c164fbd
Feed Name: Security Boulevard
Threat Score
AppOmni disclosed a ServiceNow vulnerability called “BodySnatcher” (CVE-2025-12420) that permitted unauthenticated user impersonation using only an email address, bypassing MFA and SSO and enabling creation of privileged AI agents via the Virtual Agent API; ServiceNow has issued a patch and there are no reported active exploitations, while researchers warn of high blast radius risks from compromised AI agents and urge stronger controls and preparedness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
