CVE-2025-12420
Last modified
CVE-2025-12420 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. EPSS estimates a 45.49% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:H/U:Amber
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Servicenow | Now Assist Ai Agents | < 5.1.18 |
| Servicenow | Now Assist Ai Agents | >= 5.2.0, < 5.2.19 |
| Servicenow | Virtual Agent Api | < 3.15.2 |
| Servicenow | Virtual Agent Api | >= 4.0.0, < 4.0.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-12420?
How severe is CVE-2025-12420?
How do I fix CVE-2025-12420?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12415The MapMap plugin for WordPress is vulnerable to Cross-Site …6.1
- CVE-2025-12416The Pagerank Tools plugin for WordPress is vulnerable to Sto…6.1
- CVE-2025-12417The SurveyFunnel – Survey Plugin for WordPress plugin for Wo…6.4
- CVE-2025-12418Potential Denial of Service issue in all supported versions …5.6
- CVE-2025-12419Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, …9.9
- CVE-2025-1242The administrative credentials can be extracted through appl…9.3
- CVE-2025-12421Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10…9.9
- CVE-2025-12422Vulnerable Upgrade Feature (Arbitrary File Write) may lead t…9.8
- CVE-2025-12423Protocol manipulation might lead to denial of service.This i…7.5
- CVE-2025-12424Privilege Escalation through SUID-bit Binary.This issue affe…9.8
- CVE-2025-12425Local Privilege Escalation.This issue affects BLU-IC2: throu…7.8
- CVE-2025-12426The Quiz Maker plugin for WordPress is vulnerable to Sensiti…7.5
Are you affected by CVE-2025-12420?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
