CVE 9.3 CRITICAL

Unauthenticated Privilege Escalation in ServiceNow AI Platform_CVE-2025-12420

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/S:N/AU:Y/R:U/V:C/RE:H/U:Amber

Description

A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform.

ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.

AI Analysis

Unauthenticated privilege escalation vulnerability in ServiceNow AI Platform

Basic Information

ID CVE-2025-12420
Source SN
Published Jan 12, 2026 at 21:29
Modified Jan 12, 2026 at 21:46

Affected Product

Vendor ServiceNow
Product Now Assist AI Agents
Version 5.0.26
Affected Versions ServiceNow Now Assist AI Agents 5.0.26
ServiceNow Virtual Agent API 0
ServiceNow Virtual Agent API 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor ServiceNow
Product Now Assist AI Agents
Version 5.0.26

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.