← All CVEs & advisories

ServiceNow CVE-2025-12420

ServiceNow Privilege Escalation

PrivEscCVSS 4.0 9.3Priority 19Disclosed 2026-01-12Verified

Risk & exploitation

PriorityMedium · 19/100
EPSS0.001 · 16.6th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform.

ServiceNow has addressed this vulnerability by deploying a relevant security update to  hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.

Version matrix VERIFIED (2026-06-08) against the ServiceNow-authored CVE Record + NVD CPE + AppOmni's disclosure. Delivered via Store apps, so the Layer-1 funnel returns NEEDS REVIEW with the verified component versions above — not a release/patch check. Detection signals (Layer 2) are still pending authoring; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
Now Assist AI Agents (sn_aia) 5.1.x5.1.18
Now Assist AI Agents (sn_aia) 5.2.x5.2.19
Virtual Agent API (sn_va_as_service) 3.x3.15.2
Virtual Agent API (sn_va_as_service) 4.x4.0.4
Source & attribution

Component fixed-in from NVD CPE (https://nvd.nist.gov/vuln/detail/CVE-2025-12420), the ServiceNow-authored CVE Record (CNA shortName: SN, https://cveawg.mitre.org/api/cve/CVE-2025-12420), and AppOmni's disclosure (https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/) — three concurring sources, retrieved 2026-06-08. The two Now Assist AI Agents branches (5.1.x→5.1.18, 5.2.x→5.2.19) and two Virtual Agent API branches (3.x→3.15.2, 4.x→4.0.4) are unambiguous. Hosted instances were remediated server-side by ServiceNow in Oct 2025 (credential rotation, no release patch); self-hosted and partner customers upgrade the Store apps.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2025-12420

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.