PT-2026-2305 · Servicenow · Servicenow Ai Platform

CVE-2025-12420

·

Published

2026-01-12

·

Updated

2026-06-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Now Assist AI Agents versions prior to 5.1.18 and 5.2.19 Virtual Agent API versions prior to 3.15.2 and 4.0.4 ServiceNow AI Platform (affected versions not specified)
Description A flaw in the ServiceNow AI Platform allows an unauthenticated attacker to impersonate any user, including administrators, and perform operations the impersonated user is entitled to execute. The issue stems from broken access controls and a hardcoded static secret identical across all worldwide instances, which allows attackers to bypass Multi-Factor Authentication (MFA) and Single Sign-On (SSO). Specifically, the Virtual Agent API endpoint failed to perform per-action authorization verification on tool calls, creating a gap where authentication at the perimeter did not translate to authorization within the workflow. This could enable unauthorized data exfiltration, record manipulation, and privilege escalation within sensitive business workflows.
Recommendations Update Now Assist AI Agents to version 5.1.18 or 5.2.19. Update Virtual Agent API to version 3.15.2 or 4.0.4. Apply the security updates provided by ServiceNow for self-hosted instances and hosted customers with unique configurations.

Fix

LPE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12420

Affected Products

Servicenow Ai Platform