BodySnatcher – New Vulnerability Allows Attacker to Impersonate Any ServiceNow User

A critical vulnerability in ServiceNow’s Virtual Agent API and the Now Assist AI Agents application has been discovered, allowing unauthenticated attackers to impersonate any user and execute privileged AI agents remotely. Security researcher Aaron Costello from AppOmni disclosed the flaw, tracked as CVE-2025-12420, which combines a hardcoded platform-wide secret with insecure account-linking logic to bypass […]

The post BodySnatcher – New Vulnerability Allows Attacker to Impersonate Any ServiceNow User appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: