CVE-2025-12420
massUnauthenticated User Impersonation in ServiceNow AI Platform
CVE-2025-12420 is a critical permission-preservation flaw (CWE-250) in the ServiceNow AI Platform that lets an unauthenticated, network-attainable attacker impersonate another user with no privileges, user interaction, or special conditions required. Once impersonating a victim, the attacker can perform every operation that user is entitled to perform, with high impact on confidentiality, integrity, and availability across the affected scope. The issue affects instances using the Now Assist AI Agents and Virtual Agent API components, in both ServiceNow-hosted and self-hosted/partner deployments. ServiceNow deployed the fix to hosted instances in October 2025 and shipped security updates to self-hosted, partner, and uniquely configured hosted customers, and addressed the flaw in listed Store App versions. There is no public proof-of-concept and the flaw is not yet in CISA KEV, but its EPSS of 49.1% (99th percentile) indicates a high near-term probability of exploitation, so unpatched self-hosted instances remain the main residual risk.
What to do: Self-hosted, partner, and uniquely configured hosted customers should promptly apply the ServiceNow security update or upgrade, and customers using the affected Store Apps should upgrade Now Assist AI Agents and Virtual Agent API to the fixed listed versions in ServiceNow's advisory; hosted-instance customers should verify ServiceNow applied the October 2025 fix. Review logs for anomalous impersonation activity (unexpected impersonation or swap-by events) to detect possible abuse, since exploitation requires no authentication or user interaction.
| ServiceNow Now Assist AI Agents (ServiceNow AI Platform) | — |
| ServiceNow Virtual Agent API (ServiceNow AI Platform) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.
- Vendors
- servicenow
- Products
- now assist ai agents, virtual agent api
- Weakness
- CWE-250
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:H/U:Amber