Categories: Cyber Security News

BodySnatcher Vulnerability Allows Attackers to Impersonate Any ServiceNow User

Security researchers have disclosed a critical vulnerability in ServiceNow’s Virtual Agent API and Now Assist AI Agents application, tracked as CVE-2025-12420.

Dubbed “BodySnatcher,” this authentication flaw allows unauthenticated attackers to impersonate any ServiceNow user using only their email address.

The vulnerability completely bypasses multi-factor authentication (MFA) and single sign-on (SSO) controls, enabling attackers to execute privileged AI workflows and establish persistent backdoor access through malicious administrator accounts.

Vulnerability Mechanism

The BodySnatcher exploit chains two critical security misconfigurations within ServiceNow’s AI agent infrastructure.

The BodySnatcher exploit-chain at a high-level

First, all ServiceNow instances worldwide ship with an identical static client secret hardcoded in AI Agent channel providers, creating a universal authentication bypass mechanism.

Second, the auto-linking mechanism for account association requires only an email address, without enforcing MFA, allowing any attacker with the shared token to impersonate legitimate users.

The attack unfolds in two stages. An attacker begins by sending an HTTP POST request to the /api/sn_va_as_service/bot/integration endpoint, supplying the hardcoded shared token “servicenowexternalagent” and the target’s email address.

The auto-linking mechanism automatically associates this external request with the legitimate ServiceNow user account.

After waiting 8-10 seconds for the AI agent’s confirmation, the attacker sends a follow-up payload that authorizes malicious actions, such as user creation, role assignment, or password reset, via standard workflows.

In proof-of-concept demonstrations, attackers successfully created administrator accounts, assigned elevated privileges, and gained complete platform control without possessing legitimate credentials or authenticating through SSO.

This represents a complete authentication bypass affecting any on-premise ServiceNow deployment.

ServiceNow removed the Record Management AI Agent from default installations as a patch measure, though organizational custom agents remain vulnerable if misconfigured.

A view of the impersonation attack from an internal user’s perspective

On-premise customers should immediately upgrade to patched versions. Security teams must enforce MFA for Virtual Agent provider account linking, establish mandatory approval workflows for AI agent deployments through AI Control Tower, and conduct quarterly audits to identify unused AI agents.

Metric Details
CVE Identifier CVE-2025-12420
Vulnerability Type Broken Authentication & Agentic Hijacking
CVSS Score Critical
Attack Vector Network-based, Unauthenticated
Affected Systems ServiceNow On-Premise (Cloud customers unaffected)
Authentication Required No
User Interaction Required No

Affected Versions and Patch Timeline

Application Affected Versions Fixed Versions Patch Date
Now Assist AI Agents (sn_aia) 5.0.24 – 5.1.17, 5.2.0 – 5.2.18 5.1.18, 5.2.19 January 2026
Virtual Agent API (sn_va_as_service) ≤ 3.15.1, 4.0.0 – 4.0.3 3.15.2, 4.0.4 January 2026

Organizations running affected ServiceNow versions should prioritize patching to prevent account takeover attacks targeting critical IT service management and AI automation workflows.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post BodySnatcher Vulnerability Allows Attackers to Impersonate Any ServiceNow User appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Conan O’Brien Will Return to Host the Oscars for Third Consecutive Year

Guess they weren’t kidding with that “Oscars host for life” sketch at last year’s show.…

4 minutes ago

Christopher Nolan Confirms Casting Twist for The Odyssey, With One Actor Playing Dual Roles

Christopher Nolan has confirmed a casting twist for his upcoming “mythic action epic,” The Odyssey.…

2 hours ago

Christopher Nolan Confirms Casting Twist for The Odyssey, With One Actor Playing Dual Roles

Christopher Nolan has confirmed a casting twist for his upcoming “mythic action epic,” The Odyssey.…

2 hours ago

Save Up to $1,000 Off the Asus ROG Flow Z13 Gaming Ultra-Portable Laptop and Tablet Hybrid

For this week only, Best Buy is offering a rare deal on a compact convertible…

2 hours ago

Microsoft Patch Tuesday May 2026 – 120 Vulnerabilities Fixed, Including 29 Critical RCE Flaws

Microsoft’s May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across…

3 hours ago

Fortinet Patches Five Vulnerabilities Across FortiAP, FortiOS, and Enterprise Products

Fortinet released security advisories on May 12, 2026, addressing five vulnerabilities spanning its wireless access…

3 hours ago

This website uses cookies.