Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

A lifetime of gentle screen time for your child is on sale for just $45 until June 14th

HelloFresh has released an exclusive discount code – get 10 free meals and a Zwilling Dragon Wok

Bob Dylan performs ‘You Ain’t Goin’ Nowhere’ for the first time in 14 years

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » ServiceNow fixes critical AI platform flaw that allows unauthenticated user impersonation
Celebrities

ServiceNow fixes critical AI platform flaw that allows unauthenticated user impersonation

By January 13, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 13, 2026Ravi LakshmananVulnerabilities / SaaS Security

ServiceNow has revealed details of a critical security flaw affecting the ServiceNow AI platform that is currently being patched. This flaw could allow an unauthenticated user to impersonate another user and perform arbitrary actions as that user.

This vulnerability was tracked as CVE-2025-12420 and had a CVSS score of 9.3 out of 10.0.

“This problem is […] “An unauthenticated user could impersonate another user and perform actions that the impersonated user could perform,” the company said in an advisory published Monday.

This shortcoming was addressed by ServiceNow on October 30, 2025, by deploying a security update to the majority of its hosted instances, and the company also shared the patch with ServiceNow partners and self-hosted customers.

cyber security

The following version includes the fix for CVE-2025-12420 –

Now Assist AI Agent (sn_aia) – 5.1.18 and above and 5.2.19 and above Virtual Agent API (sn_va_as_service) – 3.15.2 and above and 4.0.4 and above

ServiceNow credits Aaron Costello, head of SaaS security research at AppOmni, with discovering and reporting the vulnerability in October 2025. Although there is no evidence that this vulnerability has been exploited, users are encouraged to apply the appropriate security updates as soon as possible to mitigate the potential threat.

The disclosure comes nearly two months after AppOmni revealed that malicious attackers could exploit the default configuration of ServiceNow’s Now Assist generative artificial intelligence (AI) platform and leverage its agent capabilities to perform secondary prompt injection attacks.

This issue can then be weaponized to perform unauthorized actions, allowing attackers to copy and extract sensitive corporate data, modify records, or escalate privileges.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleConverge Bio raises $25 million with support from Bessemer and executives from Meta, OpenAI, and Wiz
Next Article What should we learn from how attackers leverage AI in 2025?

Related Posts

Aubrey Plaza wears Chanel Coco Beach Maternity Black Tie at 2026 Tony’s

June 8, 2026

Pink and daughter Willow bring textured drama to the 2026 Tony Awards

June 7, 2026

Princess Charlene of Monaco is enthusiastic about Monaco F1 Grand Prix

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

A lifetime of gentle screen time for your child is on sale for just $45 until June 14th

HelloFresh has released an exclusive discount code – get 10 free meals and a Zwilling Dragon Wok

Bob Dylan performs ‘You Ain’t Goin’ Nowhere’ for the first time in 14 years

A$AP Rocky closes Government Ball 2026 with surprise guest Tokisha: Setlist

Trending Posts

Bob Dylan performs ‘You Ain’t Goin’ Nowhere’ for the first time in 14 years

June 8, 2026

A$AP Rocky closes Government Ball 2026 with surprise guest Tokisha: Setlist

June 8, 2026

Niall Horan says he will return to Australia in early 2027

June 8, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.