Cxtoday
Critical AI Security Flaw in ServiceNow Leads to User Impersonation Risk
First seen 14 Jan 2026, 17:51 UTC
•



+2
•79% similarity
•46.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
AppOmni identified a critical security vulnerability in ServiceNow's AI platform that could allow unauthenticated users to impersonate legitimate users and perform unauthorized actions. The flaw, designated CVE-2025-12420, was discovered in October 2025 and had a severity score of 9.3 out of 10. ServiceNow implemented fixes for most hosted instances on October 30, 2025, and provided patches to partners and self-hosted customers.
ThreatCluster AI