PT-2026-2305 · Servicenow · Servicenow Ai Platform
CVE-2025-12420
·
Published
2026-01-12
·
Updated
2026-06-30
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Now Assist AI Agents versions prior to 5.1.18 and 5.2.19
Virtual Agent API versions prior to 3.15.2 and 4.0.4
ServiceNow AI Platform (affected versions not specified)
Description
A flaw in the ServiceNow AI Platform allows an unauthenticated attacker to impersonate any user, including administrators, and perform operations the impersonated user is entitled to execute. The issue stems from broken access controls and a hardcoded static secret identical across all worldwide instances, which allows attackers to bypass Multi-Factor Authentication (MFA) and Single Sign-On (SSO). Specifically, the
Virtual Agent API endpoint failed to perform per-action authorization verification on tool calls, creating a gap where authentication at the perimeter did not translate to authorization within the workflow. This could enable unauthorized data exfiltration, record manipulation, and privilege escalation within sensitive business workflows.Recommendations
Update Now Assist AI Agents to version 5.1.18 or 5.2.19.
Update Virtual Agent API to version 3.15.2 or 4.0.4.
Apply the security updates provided by ServiceNow for self-hosted instances and hosted customers with unique configurations.
Fix
LPE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Servicenow Ai Platform