ServiceNow CVE-2025-12420
ServiceNow Privilege Escalation
Risk & exploitation
EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform.
ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.
Version matrix VERIFIED (2026-06-08) against the ServiceNow-authored CVE Record + NVD CPE + AppOmni's disclosure. Delivered via Store apps, so the Layer-1 funnel returns NEEDS REVIEW with the verified component versions above — not a release/patch check. Detection signals (Layer 2) are still pending authoring; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Now Assist AI Agents (sn_aia) 5.1.x | 5.1.18 |
| Now Assist AI Agents (sn_aia) 5.2.x | 5.2.19 |
| Virtual Agent API (sn_va_as_service) 3.x | 3.15.2 |
| Virtual Agent API (sn_va_as_service) 4.x | 4.0.4 |
Source & attribution
Component fixed-in from NVD CPE (https://nvd.nist.gov/vuln/detail/CVE-2025-12420), the ServiceNow-authored CVE Record (CNA shortName: SN, https://cveawg.mitre.org/api/cve/CVE-2025-12420), and AppOmni's disclosure (https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/) — three concurring sources, retrieved 2026-06-08. The two Now Assist AI Agents branches (5.1.x→5.1.18, 5.2.x→5.2.19) and two Virtual Agent API branches (3.x→3.15.2, 4.x→4.0.4) are unambiguous. Hosted instances were remediated server-side by ServiceNow in Oct 2025 (credential rotation, no release patch); self-hosted and partner customers upgrade the Store apps.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(d)
- NIS2 Art.21§2(i)
- DORA Art.9§1
- DORA Art.9§2
- DORA RTS Art.10
- DORA RTS Art.11
- ISO A.8.8
- ISO A.8.9
- ISO A.5.17
- GDPR Art.32§1(b)
Decision support, not a reporting determination.
References
- https://github.com/advisories/GHSA-mwg5-cwh8-88m5
- https://nvd.nist.gov/vuln/detail/CVE-2025-12420
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2587329
- https://www.cve.org/CVERecord?id=CVE-2025-12420
- https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.