ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation
These articles are AI-generated summaries. Please check the original sources for full details.
ServiceNow AI Platform Vulnerability: CVE-2025-12420
ServiceNow addressed a critical vulnerability (CVE-2025-12420) in its AI Platform, dubbed “BodySnatcher” by AppOmni, which permitted unauthenticated user impersonation. The flaw, with a CVSS score of 9.3, potentially allowed attackers to perform actions with the privileges of any user.
Why This Matters
Ideal access control models assume strong authentication and authorization, but real-world implementations often contain vulnerabilities like hardcoded secrets or flawed account linking logic. This flaw demonstrates how a combination of these issues can bypass MFA and SSO, leading to complete account takeover and potentially significant data breaches or system compromise – a risk amplified by the increasing reliance on AI-driven automation within enterprise systems.
Key Insights
- CVE-2025-12420, 2025: A critical vulnerability in ServiceNow’s AI Platform allowed unauthenticated impersonation.
- Second-order prompt injection: Exploiting default configurations in generative AI platforms to execute unauthorized actions.
- AppOmni research, 2025: Discovered and reported the vulnerability, highlighting the risks associated with AI platform security.
Working Example
# No code example available in the provided context.
Practical Applications
- Use Case: ServiceNow instances utilizing Now Assist AI Agents or Virtual Agent API require immediate patching to prevent unauthorized access.
- Pitfall: Trusting email addresses as a primary authentication factor, particularly when integrated with AI agents, can bypass robust security controls like MFA and SSO.
References:
Continue reading
Next article
Shadow#Reactor Uses Text Files to Deliver Remcos RAT
Related Content
Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation
Grafana addresses a critical CVSS 10.0 vulnerability in SCIM allowing user impersonation and privilege escalation in versions 12.x.
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
Attackers are actively exploiting critical FortiGate vulnerabilities (CVE-2025-59718 & CVE-2025-59719) with a CVSS score of 9.8, prompting urgent patching recommendations.
Samsung Zero-Day Flaw Exploited to Deploy LANDFALL Android Spyware in Middle East
A critical Samsung Galaxy vulnerability (CVE-2025-21042) was exploited as a zero-day to deploy the LANDFALL spyware via WhatsApp images, targeting users in the Middle East before a patch in April 2025.