ZeroHour

CVE-2025-12420

mass

Unauthenticated User Impersonation in ServiceNow AI Platform

CVSS 4.0
9.3 critical
EPSS
49%p99
Published
()
Modified
AI analysis

CVE-2025-12420 is a critical permission-preservation flaw (CWE-250) in the ServiceNow AI Platform that lets an unauthenticated, network-attainable attacker impersonate another user with no privileges, user interaction, or special conditions required. Once impersonating a victim, the attacker can perform every operation that user is entitled to perform, with high impact on confidentiality, integrity, and availability across the affected scope. The issue affects instances using the Now Assist AI Agents and Virtual Agent API components, in both ServiceNow-hosted and self-hosted/partner deployments. ServiceNow deployed the fix to hosted instances in October 2025 and shipped security updates to self-hosted, partner, and uniquely configured hosted customers, and addressed the flaw in listed Store App versions. There is no public proof-of-concept and the flaw is not yet in CISA KEV, but its EPSS of 49.1% (99th percentile) indicates a high near-term probability of exploitation, so unpatched self-hosted instances remain the main residual risk.

What to do: Self-hosted, partner, and uniquely configured hosted customers should promptly apply the ServiceNow security update or upgrade, and customers using the affected Store Apps should upgrade Now Assist AI Agents and Virtual Agent API to the fixed listed versions in ServiceNow's advisory; hosted-instance customers should verify ServiceNow applied the October 2025 fix. Review logs for anomalous impersonation activity (unexpected impersonation or swap-by events) to detect possible abuse, since exploitation requires no authentication or user interaction.

Affected
ServiceNow Now Assist AI Agents (ServiceNow AI Platform)
ServiceNow Virtual Agent API (ServiceNow AI Platform)
Estimated exposure
massmillions of end users across thousands of enterprise customer instances (hosted fleet largely patched in Oct 2025; residual exposure concentrated in unpatched… — ServiceNow is a top-tier enterprise SaaS platform serving roughly 8,000 enterprise customers with millions of licensed users, and the affected AI Agent/Virtual Agent components are deployed broadly, though the precise count of instances…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.

Vendors
servicenow
Products
now assist ai agents, virtual agent api
Weakness
CWE-250
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:H/U:Amber

In the news