BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow
ID: 1b35ffe2-dc46-508f-ac24-9e1f8c0d10d4
STIX ID: report--1b35ffe2-dc46-508f-ac24-9e1f8c0d10d4
Feed Name: Security Boulevard
Date Published: 2026-01-13
Date Updated: 2026-04-22
Author: Aaron Costello, Chief of Security Research, AppOmni
### Executive Summary This report describes “BodySnatcher” (CVE-2025-12420), a critical agentic-AI vulnerability in ServiceNow where a platform-wide static provider secret combined with insecure auto-linking allowed unauthenticated attackers (knowing only an email) to impersonate users, bypass MFA/SSO, and remotely invoke privileged AI agents to create admin backdoors; the document details the Virtual Agent and A2A internals, provides PoC exploit requests, and gives mitigation and governance recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
