<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/servicenow-ai-platform-vulnerability-critical-impersonation-flaw-patched-wzaqd15et" -->

---
title: ServiceNow AI Platform Vulnerability: Critical...
description: AppOmni discovered BodySnatcher (CVE-2025-12420), a critical vulnerability in ServiceNow&#x27;s AI platform that allowed unauthenticated attackers to impersonate...
canonical: https://daily.dev/posts/servicenow-ai-platform-vulnerability-critical-impersonation-flaw-patched-wzaqd15et
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: ServiceNow AI Platform Vulnerability: Critical Impersonation Flaw Patched | daily.dev
og:description: AppOmni discovered BodySnatcher (CVE-2025-12420), a critical vulnerability in ServiceNow&#x27;s AI platform that allowed unauthenticated attackers to impersonate...
og:url: https://daily.dev/posts/servicenow-ai-platform-vulnerability-critical-impersonation-flaw-patched-wzaqd15et
og:image: https://api.daily.dev/og/posts/wzAqd15ET.png
og:image:alt: ServiceNow AI Platform Vulnerability: Critical Impersonation Flaw Patched
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# ServiceNow AI Platform Vulnerability: Critical Impersonation Flaw Patched

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

AppOmni discovered BodySnatcher (CVE-2025-12420), a critical vulnerability in ServiceNow's AI platform that allowed unauthenticated attackers to impersonate users via email addresses, bypassing MFA and SSO. The flaw enabled creation of malicious AI agents with elevated privileges and access to external environments. The vulnerability arose from layering new AI capabilities over older, insecure authentication protocols in the Virtual Agent API. ServiceNow patched the issue on October 30, 2025, by rotating credentials and removing exploitable functionalities. Organizations are advised to enforce MFA, review custom AI agents, and conduct regular audits despite no evidence of active exploitation.

## Content

A critical security vulnerability, known as BodySnatcher (CVE-2025-12420), has been unearthed in ServiceNow's AI platform by AppOmni. This vulnerability allowed unauthenticated attackers to impersonate users simply by using their email addresses, effectively bypassing multi-factor authentication (MFA) and single sign-on (SSO). Attackers could exploit this flaw to create malicious AI agents with elevated privileges, gaining access to external environments through ServiceNow's Virtual Agent API.

Discovered by AppOmni researcher Aaron Costello, BodySnatcher emerges as a significant concern given the increasingly widespread adoption of AI agents within enterprises. These AI agents can potentially access sensitive data and automated workflows, making the blast radius of such vulnerabilities much wider compared to traditional breaches.

The vulnerability stemmed from integration issues where new AI agent capabilities were layered over older, less secure authentication protocols of the Virtual Agent API, which did not initially require ServiceNow accounts. This security lapse allowed attackers to impersonate users and execute workflows with administrative privileges, potentially creating backdoor access across various systems connected to ServiceNow, from HR and customer service to security infrastructures.

ServiceNow has responded by releasing a patch on October 30, 2025, addressing the issue by rotating the universal credential and removing the exploitable AI agent functionalities. The patch has been automatically applied to hosted instances and shared with partners, alleviating immediate security concerns. While there is no evidence of these vulnerabilities being actively exploited in the wild, ServiceNow advises organizations to enforce stronger security measures. These include enforcing MFA for account linking, reviewing all custom AI agents, and regularly auditing to remove any unused agents.

Despite the patch, organizations must remain vigilant. The rush to integrate AI into existing platforms can sometimes lead to overlooked security weaknesses. Custom code and third-party integrations might still harbor similar dangerous configurations, making it crucial to maintain rigorous security practices as AI technology continues to evolve.

## Similar posts on daily.dev

- [ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations](https://daily.dev/posts/servicenow-s-virtual-agent-vulnerability-shows-why-ai-security-needs-traditional-appsec-foundations-00t2r8uqf) · Snyk · 0 upvotes · 0 comments

---

Tags: [#ai](https://daily.dev/tags/ai), [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/servicenow-ai-platform-vulnerability-critical-impersonation-flaw-patched-wzaqd15et)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"ServiceNow AI Platform Vulnerability: Critical Impersonation Flaw Patched","url":"https://daily.dev/posts/servicenow-ai-platform-vulnerability-critical-impersonation-flaw-patched-wzaqd15et","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/servicenow-ai-platform-vulnerability-critical-impersonation-flaw-patched-wzaqd15et"},"datePublished":"2026-01-14T14:50:43.470Z","dateModified":"2026-01-19T07:03:54.643Z","description":"AppOmni discovered BodySnatcher (CVE-2025-12420), a critical vulnerability in ServiceNow's AI platform that allowed unauthenticated attackers to impersonate...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d583223356a1e62345d25fd730081d9e?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d583223356a1e62345d25fd730081d9e?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/servicenow-ai-platform-vulnerability-critical-impersonation-flaw-patched-wzaqd15et","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai,security,authentication,vulnerability","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"ServiceNow AI Platform Vulnerability: Critical Impersonation Flaw Patched"}]}
```

