Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Make investments Qatar Pavilion showcases Qatar’s imaginative and prescient on the World Financial Discussion board Annual Assembly 2026

January 19, 2026

A Coding Information to Understanding How Retries Set off Failure Cascades in RPC and Occasion-Pushed Architectures

January 19, 2026

Bee Community connects passengers with real-time updates

January 19, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Make investments Qatar Pavilion showcases Qatar’s imaginative and prescient on the World Financial Discussion board Annual Assembly 2026
  • A Coding Information to Understanding How Retries Set off Failure Cascades in RPC and Occasion-Pushed Architectures
  • Bee Community connects passengers with real-time updates
  • Kraken Robotics Declares $35 Million in SeaPower™ Battery Gross sales
  • I wasn’t seeking to change my Kindle, however this Android e-reader made it straightforward
  • DeepSeek Founder’s Hedge Fund Delivers 56.6% Returns in 2025, Managing Over $9.8 billion
  • Weekly funding round-up! All the European startup funding rounds we tracked this week (Jan. 12-16)
  • Fiber Optic Market to Witness Robust Progress Pushed by 5G, Broadband Enlargement, and Digital Transformation
Monday, January 19
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - ServiceNow Patches Crucial AI Platform Flaw Permitting Unauthenticated Person Impersonation
Cybersecurity & Digital Rights

ServiceNow Patches Crucial AI Platform Flaw Permitting Unauthenticated Person Impersonation

NextTechBy NextTechJanuary 19, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
ServiceNow Patches Crucial AI Platform Flaw Permitting Unauthenticated Person Impersonation
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananJan 13, 2026Vulnerability / SaaS Safety

ServiceNow has disclosed particulars of a now-patched crucial safety flaw impacting its ServiceNow synthetic intelligence (AI) Platform that would allow an unauthenticated person to impersonate one other person and carry out arbitrary actions as that person.

The vulnerability, tracked as CVE-2025-12420, carries a CVSS rating of 9.3 out of 10.0. It has been codenamed BodySnatcher by AppOmni.

“This challenge […] may allow an unauthenticated person to impersonate one other person and carry out the operations that the impersonated person is entitled to carry out,” the corporate stated in an advisory launched Monday.

The shortcoming was addressed by ServiceNow on October 30, 2025, by deploying a safety replace to the vast majority of hosted situations, with the corporate additionally sharing the patches with ServiceNow companions and self-hosted prospects.

Cybersecurity

The next variations embody a repair for CVE-2025-12420 –

  • Now Help AI Brokers (sn_aia) – 5.1.18 or later and 5.2.19 or later
  • Digital Agent API (sn_va_as_service) – 3.15.2 or later and 4.0.4 or later

ServiceNow credited Aaron Costello, chief of SaaS Safety Analysis at AppOmni, with discovering and reporting the flaw in October 2025. Whereas there isn’t a proof that the vulnerability has been exploited within the wild, customers are suggested to use an applicable safety replace as quickly as attainable to mitigate potential threats.

“BodySnatcher is essentially the most extreme AI-driven vulnerability uncovered so far: Attackers may have successfully ‘distant managed’ a corporation’s AI, weaponizing the very instruments meant to simplify the enterprise,” Costello advised The Hacker Information.

In a separate report, AppOmni stated the Digital Agent integration flaw permits unauthenticated attackers to impersonate any ServiceNow person utilizing solely an electronic mail deal with, bypassing multi-factor authentication (MFA) and single sign-on (SSO) protections. Profitable exploitation may enable a menace actor to impersonate an administrator and execute an AI agent to subvert safety controls and create backdoor accounts with elevated privileges.

“By chaining a hardcoded, platform-wide secret with account-linking logic that trusts a easy electronic mail deal with, an attacker can bypass multi-factor authentication (MFA), single sign-on (SSO), and different entry controls,” Costello added. “And it is essentially the most extreme AI-driven safety vulnerability uncovered so far. With these weaknesses linked collectively, the attacker can remotely drive privileged agentic workflows as any person.”

The disclosure comes practically two months after AppOmni revealed that malicious actors can exploit default configurations in ServiceNow’s Now Help generative AI platform and leverage its agentic capabilities to conduct second-order immediate injection assaults.

The difficulty may then be weaponized to execute unauthorized actions, enabling attackers to repeat and exfiltrate delicate company information, modify information, and escalate privileges.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s traits immediately: learn extra, subscribe to our e-newsletter, and turn out to be a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

AI Brokers Are Changing into Authorization Bypass Paths

January 18, 2026

FBI Flags Quishing Assaults From North Korean APT

January 18, 2026

Shadow#Reactor Makes use of Textual content Recordsdata to Ship Remcos RAT

January 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

Make investments Qatar Pavilion showcases Qatar’s imaginative and prescient on the World Financial Discussion board Annual Assembly 2026

By NextTechJanuary 19, 2026

Make investments Qatar, the Funding Promotion Company of Qatar, will host a devoted Nation Pavilion…

A Coding Information to Understanding How Retries Set off Failure Cascades in RPC and Occasion-Pushed Architectures

January 19, 2026

Bee Community connects passengers with real-time updates

January 19, 2026
Top Trending

Make investments Qatar Pavilion showcases Qatar’s imaginative and prescient on the World Financial Discussion board Annual Assembly 2026

By NextTechJanuary 19, 2026

Make investments Qatar, the Funding Promotion Company of Qatar, will host a…

A Coding Information to Understanding How Retries Set off Failure Cascades in RPC and Occasion-Pushed Architectures

By NextTechJanuary 19, 2026

On this tutorial, we construct a hands-on comparability between a synchronous RPC-based…

Bee Community connects passengers with real-time updates

By NextTechJanuary 19, 2026

The shows are a part of TfGM’s Enhancing Journeys programme, an initiative designed to…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!