ServiceNow AI Platform Privilege Escalation Vulnerability

Home/Application Security, Cybersecurity, Internet Security, Mobile Security, Secuirty Update, Security Advisory/ServiceNow AI Platform Privilege Escalation Vulnerability

ServiceNow AI Platform Privilege Escalation Vulnerability

A serious security issue has been identified in the ServiceNow AI Platform, exposing organizations to the risk of unauthorized access and privilege escalation. The flaw allows attackers to act as legitimate users without needing to log in, making it a high-impact threat for affected environments.

The vulnerability, tracked as CVE-2025-12420, was reported by SaaS security firm AppOmni and shared with ServiceNow in October 2025. Following the report, ServiceNow moved quickly to investigate and release fixes.

How the Vulnerability Works

The issue exists within ServiceNow’s AI Platform infrastructure and allows unauthenticated attackers to impersonate valid user accounts. Once impersonation is successful, attackers inherit all permissions tied to that user.

This could allow malicious actors to:

  • Access sensitive data
  • Modify configurations
  • Perform unauthorized actions
  • Move laterally within enterprise environments

Vulnerability Details

CVE IDIssue TypeCVSS Score (v4.0)Affected Area
CVE-2025-12420Privilege Escalation9.3 (Critical)ServiceNow AI Platform

Affected Components and Fixes

The vulnerability impacts two key ServiceNow applications. Customers must ensure they are running patched versions:

ComponentMinimum Secure Version
Assist AI Agents (sn_aia)5.1.18+ or 5.2.19+
Virtual Agent API (sn_va_as_service)3.15.2+ or 4.0.4+

ServiceNow deployed fixes to most hosted environments on October 30, 2025, and also made updates available for partners and customers running self-hosted deployments. The issue has additionally been resolved in relevant Store App releases from the October 2025 maintenance cycle.

What Organizations Should Do

ServiceNow strongly advises customers to apply security updates immediately or upgrade to the required versions if they have not already done so. This applies to both hosted and self-managed environments.

Although ServiceNow has stated there is no confirmed exploitation in the wild, vulnerabilities of this nature often attract rapid attacker interest once publicly disclosed. Security teams should treat this issue as a priority.

‍Follow Us on: Linkedin, InstagramFacebook to get the latest security news!

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!