BodySnatcher Vulnerability Enables ServiceNow User Impersonation
First seen 19 Jan 2026, 18:32 UTC
•
•26
Export
Article Content
Browse articles
A critical vulnerability named 'BodySnatcher' has been identified in ServiceNow's Virtual Agent API and Now Assist AI Agents application, allowing attackers to impersonate any ServiceNow user. This flaw poses significant risks to organizations using ServiceNow, as it can lead to unauthorized access and manipulation of sensitive data.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
ServiceNow AI Platform Vulnerability Allows Remote Code Execution
City-Forum Campaign Targets Salesforce and ServiceNow Data Exposures
TeamPCP Hackers Arrested for Major Supply Chain Attacks
ServiceNow Data Breach Exposes Customer Data via API Vulnerability
Snyk Launches Evo Continuous Offensive Security for AI-Powered Pentesting
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching