CVE-2025-12420: Unauthenticated Privilege Escalation in ServiceNow AI Platform
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform.
ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances in October 2025. Security updates have also been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Additionally, the vulnerability is addressed in the listed Store App versions. We recommend that customers promptly apply an appropriate security update or upgrade if they have not already done so.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12420?
CVE-2025-12420 is considered a high-severity vulnerability due to the potential for unauthorized privilege escalation.
How do I fix CVE-2025-12420?
To fix CVE-2025-12420, update the ServiceNow AI Platform to the latest patched version provided by ServiceNow.
What type of vulnerability is CVE-2025-12420?
CVE-2025-12420 is classified as an unauthenticated privilege escalation vulnerability.
Who is affected by CVE-2025-12420?
Any users of the ServiceNow AI Platform may be affected by CVE-2025-12420 if they are running an unpatched version.
What could an attacker do with CVE-2025-12420?
An attacker exploiting CVE-2025-12420 could impersonate other users and perform sensitive operations on their behalf.