Critical AI Security Flaw in ServiceNow Leads to User Impersonation Risk

Critical AI Security Flaw in ServiceNow Leads to User Impersonation Risk

First seen 14 Jan 2026, 17:51 UTC SecuritybriefCyberscoopCxtodayItbriefScworld+2 79% similarity 46.7

Article Content

Browse articles
ThreatCluster

AppOmni identified a critical security vulnerability in ServiceNow's AI platform that could allow unauthenticated users to impersonate legitimate users and perform unauthorized actions. The flaw, designated CVE-2025-12420, was discovered in October 2025 and had a severity score of 9.3 out of 10. ServiceNow implemented fixes for most hosted instances on October 30, 2025, and provided patches to partners and self-hosted customers.

ThreatCluster AI

Community

Browse all →