ServiceNow patches critical AI platform flaw that could allow user impersonation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-12420 | Unauthenticated User Impersonation in ServiceNow AI Platform CVE-2025-12420 is a critical permission-preservation flaw (CWE-250) in the ServiceNow AI Platform that lets an unauthenticated, network-attainable attacker impersonate another user with no privileges, user interaction, or special conditions required. Once impersonating a victim, the attacker can perform every operation that user is entitled to perform, with high impact on confidentiality, integrity, and availability across the affected scope. The issue affects instances using the Now Assist AI Agents and Virtual Agent API components, in both ServiceNow-hosted and self-hosted/partner deployments. ServiceNow deployed the fix to hosted instances in October 2025 and shipped security updates to self-hosted, partner, and uniquely configured hosted customers, and addressed the flaw in listed Store App versions. There is no public proof-of-concept and the flaw is not yet in CISA KEV, but its EPSS of 49.1% (99th percentile) indicates a high near-term probability of exploitation, so unpatched self-hosted instances remain the main residual risk. Do: Self-hosted, partner, and uniquely configured hosted customers should promptly apply the ServiceNow security update or upgrade, and customers using the affected Store Apps should upgrade Now Assist AI Agents and Virtual Agent API to the fixed listed versions in ServiceNow's advisory; hosted-instance customers should verify ServiceNow applied the October 2025 fix. Review logs for anomalous impersonation activity (unexpected impersonation or swap-by events) to detect possible abuse, since exploitation requires no authentication or user interaction. | 9.3 | 49% |
| massmillions of end users across thousands of enterprise customer instances (hosted fleet largely patched in Oct 2025; residual exposure concentrated in unpatched… |
Full article691 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company says it has no evidence the bug was exploited before October’s patch, but researchers say AI agent configuration can still enable prompt-injection style abuse.
Listen to this article
0:00
Learn more.
ServiceNow has addressed a critical security vulnerability in its AI platform that could have allowed unauthenticated users to impersonate legitimate users and perform unauthorized actions, the company disclosed Monday.
The flaw, designated CVE-2025-12420 and carrying a severity score of 9.3 out of 10, was discovered by SaaS security firm AppOmni in October. ServiceNow deployed fixes to most hosted instances on Oct. 30, 2025, and provided patches to partners and self-hosted customers. The company said it has no evidence the vulnerability was exploited before the fix.
The vulnerability affected Now Assist AI Agents and Virtual Agent API components. Customers using affected versions were advised to upgrade to patched releases, which include Now Assist AI Agents version 5.1.18 or later and 5.2.19 or later, and Virtual Agent API version 3.15.2 or later and 4.0.4 or later.
The disclosure arrives as security researchers raise broader questions about the configuration and deployment of enterprise AI systems. AppOmni’s research, which led to the vulnerability discovery, also revealed that default settings in ServiceNow’s Now Assist platform could enable second-order prompt injection attacks, a sophisticated exploit method that manipulates AI agents through data they process rather than direct user input.
These attacks exploit a feature called agent discovery, which allows AI agents to communicate with each other to complete complex tasks. While designed to enhance functionality, the feature creates potential attack vectors when agents are improperly configured or grouped together without adequate controls.
In testing scenarios, researchers demonstrated that low-privileged users could embed malicious instructions in data fields that higher-privileged users’ AI agents would later process. The compromised agent could then recruit other more powerful agents to execute unauthorized actions, including accessing restricted records, modifying data, and potentially escalating user privileges.
The attacks succeeded even with ServiceNow’s prompt injection protection feature enabled, highlighting how configuration choices can undermine security controls embedded in the AI systems themselves. The researchers found that default settings automatically grouped agents into teams and marked them as discoverable, creating unintended collaboration pathways that attackers could exploit.
The research underscores a fundamental challenge in enterprise AI deployment: security depends not only on the underlying technology but also on how organizations configure and manage these systems. ServiceNow confirmed the behaviors identified by researchers were intentional design choices and updated its documentation to clarify configuration options.
Organizations using ServiceNow’s AI platform face the task of balancing autonomous agent capabilities against security risks. The research suggests several mitigation strategies, including requiring human supervision for agents with powerful capabilities, segmenting agents into isolated teams based on their functions, and monitoring agent behavior for deviations from expected patterns.
You can find more information on the vulnerability on ServiceNow’s website.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/servicenow-fixes-critical-ai-vulnerability-cve-2025-12420/