Security researchers disclosed a critical vulnerability, dubbed “BodySnatcher” (CVE-2025-12420), in ServiceNow’s Virtual Agent API that combined a hardcoded platform-wide secret with insecure account-linking logic. An unauthenticated attacker who knew only a target’s email address could impersonate that user, bypass MFA and SSO, and gain privileged access to AI agents — including the Now Assist and Record Management AI Agent applications — potentially creating backdoor admin accounts with full platform access.
ServiceNow notified customers and released patches on October 30, 2025. The flaw affected on-premise customers; ServiceNow subsequently removed the Record Management AI Agent. No exploitation in the wild was reported.