Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

India has reportedly told quick commerce companies to withdraw their 10-minute delivery promises.

Eleven Labs CEO says voice AI startup generated over $330 million in ARR last year

Beyond the Pixel: Why TwinH is Replacing the Avatar as the Anchor of Digital Immortality

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » ServiceNow fixes critical AI platform flaw that allows unauthenticated user impersonation
Identity

ServiceNow fixes critical AI platform flaw that allows unauthenticated user impersonation

userBy userJanuary 13, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 13, 2026Ravi LakshmananVulnerabilities / SaaS Security

ServiceNow has revealed details of a critical security flaw affecting the ServiceNow AI platform that is currently being patched. This flaw could allow an unauthenticated user to impersonate another user and perform arbitrary actions as that user.

This vulnerability was tracked as CVE-2025-12420 and had a CVSS score of 9.3 out of 10.0.

“This problem is […] “An unauthenticated user could impersonate another user and perform actions that the impersonated user could perform,” the company said in an advisory published Monday.

This shortcoming was addressed by ServiceNow on October 30, 2025, by deploying a security update to the majority of its hosted instances, and the company also shared the patch with ServiceNow partners and self-hosted customers.

cyber security

The following version includes the fix for CVE-2025-12420 –

Now Assist AI Agent (sn_aia) – 5.1.18 and above and 5.2.19 and above Virtual Agent API (sn_va_as_service) – 3.15.2 and above and 4.0.4 and above

ServiceNow credits Aaron Costello, head of SaaS security research at AppOmni, with discovering and reporting the vulnerability in October 2025. Although there is no evidence that this vulnerability has been exploited, users are encouraged to apply the appropriate security updates as soon as possible to mitigate the potential threat.

The disclosure comes nearly two months after AppOmni revealed that malicious attackers could exploit the default configuration of ServiceNow’s Now Assist generative artificial intelligence (AI) platform and leverage its agent capabilities to perform secondary prompt injection attacks.

This issue can then be weaponized to perform unauthorized actions, allowing attackers to copy and extract sensitive corporate data, modify records, or escalate privileges.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleConverge Bio raises $25 million with support from Bessemer and executives from Meta, OpenAI, and Wiz
Next Article What should we learn from how attackers leverage AI in 2025?
user
  • Website

Related Posts

From MCP and tool access to shadow API key sprawl

January 13, 2026

New advanced Linux VoidLink malware targets cloud and container environments

January 13, 2026

What should we learn from how attackers leverage AI in 2025?

January 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

India has reportedly told quick commerce companies to withdraw their 10-minute delivery promises.

Eleven Labs CEO says voice AI startup generated over $330 million in ARR last year

Beyond the Pixel: Why TwinH is Replacing the Avatar as the Anchor of Digital Immortality

From MCP and tool access to shadow API key sprawl

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.