HomeSecurityCritical vulnerability in ServiceNow allows privilege escalation

Critical vulnerability in ServiceNow allows privilege escalation

A critical security threat affects deployments of the ServiceNow AI, allowing unauthenticated attackers to impersonate legitimate users and perform unauthorized actions.

See also: ServiceNow acquires identity security company Veza

ServiceNow

The vulnerability, codenamed CVE-2025-12420, was discovered by SaaS security firm AppOmni and disclosed to ServiceNow in October 2025, leading to immediate remediation actions. The privilege escalation flaw in the ServiceNow AI platform infrastructure allows attackers without access credentials to assume the identity of authorized users.

After successful impersonation, attackers gain access to all functions and privileges of the compromised account, which can lead to unauthorized access to data, settings changes, and lateral movement within corporate environments.

ServiceNow addressed the vulnerability on October 30, 2025, by deploying security updates to the vast majority of hosted installations. It also provided updates to partners and customers with self-managed deployments. The vulnerability has also been resolved in specific Store app builds released as part of the October 2025 security maintenance cycle.

See also: ServiceNow AI Agents: Abuse of default settings for prompt injection

Critical vulnerability in ServiceNow allows privilege escalation

Organizations using both hosted and self-managed ServiceNow environments should prioritize remediating this vulnerability immediately, due to its critical severity and increased likelihood of exploitation following its public disclosure.

At this time, ServiceNow says there is no evidence of active exploitation online. However, the time frame between public disclosure and widespread attacks is typically short, making it necessary for security teams to mobilize quickly.

This collaborative approach allowed suppliers to develop and implement fixes before public announcement, reducing the exposure time of customers' environments.

See also: New flaw in ServiceNow allows data extraction

Critical vulnerability in ServiceNow allows privilege escalation

Organizations relying on ServiceNow AI platform components should review the full security bulletin. Implementation guidance is available through the official support documentation to ensure comprehensive remediation of the vulnerability across their infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS