Close Menu
clearpathinsight.org
  • AI Studies
  • AI in Biz
  • AI in Tech
  • AI in Health
  • Supply AI
    • Smart Chain
    • Track AI
    • Chain Risk
  • More
    • AI Logistics
    • AI Updates
    • AI Startups

Amazon launches AI healthcare tool for One Medical members

January 23, 2026

Workday CEO calls AI software sales narrative ‘exaggerated’

January 23, 2026

AI in the exam room: combining technology and human contact

January 23, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
clearpathinsight.org
Subscribe
  • AI Studies
  • AI in Biz
  • AI in Tech
  • AI in Health
  • Supply AI
    • Smart Chain
    • Track AI
    • Chain Risk
  • More
    • AI Logistics
    • AI Updates
    • AI Startups
clearpathinsight.org
Home»AI Research Updates»ServiceNow fixes critical AI platform flaw that could enable user impersonation
AI Research Updates

ServiceNow fixes critical AI platform flaw that could enable user impersonation

January 15, 2026003 Mins Read
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
Follow Us
Google News Flipboard
Ea8b076b398ee48b71cfaecf898c582b.jpeg
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

ServiceNow has fixed a critical security vulnerability in its AI platform that could have allowed unauthenticated users to impersonate legitimate users and perform unauthorized actions, the company revealed Monday.

The fault, designated CVE-2025-12420 and having a severity score of 9.3 out of 10, was discovered by SaaS security company AppOmni in October. ServiceNow deployed fixes to most hosted instances on October 30, 2025 and provided fixes to partners and self-hosted customers. The company said it had no evidence the vulnerability had been exploited before the patch.

The vulnerability affected the Now Assist AI Agents and Virtual Agent API components. Customers using affected versions have been advised to upgrade to the patched versions, which include Now Assist AI Agents version 5.1.18 or later and 5.2.19 or later, and Virtual Agent API version 3.15.2 or later and 4.0.4 or later.

The disclosure comes as security researchers raise broader questions about the configuration and deployment of enterprise AI systems. AppOmni Researchwhich led to the discovery of the vulnerability, also revealed that the default settings of ServiceNow’s Now Assist platform could enable second-order rapid injection attacks, a sophisticated exploitation method that manipulates AI agents through the data they process rather than direct user input.

These attacks leverage a feature called agent discovery, which allows AI agents to communicate with each other to perform complex tasks. Although designed to improve functionality, this feature creates potential attack vectors when agents are misconfigured or grouped together without adequate controls.

In test scenarios, the researchers demonstrated that low-privileged users could embed malicious instructions into data fields that the more privileged users’ AI agents would later process. The compromised agent could then recruit other, more powerful agents to perform unauthorized actions, including accessing restricted records, modifying data, and potentially escalating user privileges.

The attacks were successful even with ServiceNow’s Rapid Injection Protection feature enabled, highlighting how configuration choices can undermine security controls built into the AI ​​systems themselves. Researchers found that the default settings automatically grouped agents into teams and marked them as discoverable, creating unintended collaboration pathways that attackers could exploit.

The research highlights a fundamental challenge in enterprise AI deployment: security depends not only on the underlying technology, but also on how organizations configure and manage these systems. ServiceNow confirmed that the behaviors identified by researchers were intentional design choices and updated its documentation to clarify configuration options.

Organizations using ServiceNow’s AI platform face the task of balancing autonomous agent capabilities and security risks. Research suggests several mitigation strategies, including requiring human supervision for agents with powerful capabilities, segmenting agents into isolated teams based on their functions, and monitoring agent behavior to detect deviations from expected patterns.

You can find more information about the vulnerability at The ServiceNow website.

Greg Otto

Written by Greg Otto

Greg Otto is Editor-in-Chief of CyberScoop, overseeing all editorial content on the website. Greg has led cybersecurity news coverage that has won various awards, including honors from the Society of Professional Journalists and the American Society of Business Publication Editors. Before joining Scoop News Group, Greg worked for the Washington Business Journal, US News & World Report and WTOP Radio. He has a degree in broadcast journalism from Temple University.

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Posts

Experts warn Canada risks losing top researchers in ‘global war for AI talent’

January 22, 2026

$30 million awarded to Binghamton University for new AI research center | News

January 21, 2026

Next-generation medical image interpretation with MedGemma 1.5 and medical speech synthesis with MedASR

January 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Categories
  • AI Applications & Case Studies (54)
  • AI in Business (277)
  • AI in Healthcare (249)
  • AI in Technology (263)
  • AI Logistics (47)
  • AI Research Updates (104)
  • AI Startups & Investments (223)
  • Chain Risk (69)
  • Smart Chain (91)
  • Supply AI (73)
  • Track AI (57)

Amazon launches AI healthcare tool for One Medical members

January 23, 2026

Workday CEO calls AI software sales narrative ‘exaggerated’

January 23, 2026

AI in the exam room: combining technology and human contact

January 23, 2026

ShopSight Closes the Retail Certainty Gap with Shopper Co-Creation and Agentic AI Demand Forecasting

January 23, 2026

Subscribe to Updates

Get the latest news from clearpathinsight.

Topics
  • AI Applications & Case Studies (54)
  • AI in Business (277)
  • AI in Healthcare (249)
  • AI in Technology (263)
  • AI Logistics (47)
  • AI Research Updates (104)
  • AI Startups & Investments (223)
  • Chain Risk (69)
  • Smart Chain (91)
  • Supply AI (73)
  • Track AI (57)
Join us

Subscribe to Updates

Get the latest news from clearpathinsight.

We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Reddit
  • Telegram
  • WhatsApp
Facebook X (Twitter) Instagram Pinterest
© 2026 Designed by clearpathinsight

Type above and press Enter to search. Press Esc to cancel.