
- ServiceNow patches critical AI Platform flaw (CVE-2025-12420) enabling user impersonation
- “BodySnatcher” scored 9.3/10 and affected multiple app versions
- No exploitation seen yet; experts warn unpatched systems remain at risk post-fix
ServiceNow, one of the most popular cloud platforms for automating IT and business workflows, has said it recently patched a critical-severity vulnerability which allowed threat actors to impersonate other users and perform arbitrary actions in their stead.