Last seen August 30, 2026

FlexPLM Remote Code Execution Vulnerability

A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.

Why This Matters

Publisher reporting describes a security event affecting PTC. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether cvss is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Aug 30, 2026 20:34

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

PTCFlexPLMPTC WindchillWindchill PDMLinkAI AgentsData Leakage

Authoritative Intelligence

CVE CVE-2025-12420 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Jan 13, 2026 05:30

    BugSkan first recorded this incident.

  • ServiceNow patches critical AI platform flaw that could allow user impersonation - CyberScoop
    Jan 13, 2026 05:30

    cyberscoop.com ยท Vulnerability

  • ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation - The Hacker News
    Jan 13, 2026 05:30

    thehackernews.com ยท Vulnerability

  • ServiceNow patches critical AI Platform vulnerability enabling user impersonation - SC Media
    Jan 15, 2026 05:30

    scworld.com ยท Vulnerability

  • CLOP Is Mass-Exploiting PTC Windchill at Scale. Every AI Agent Connected to It Inherits the Breach. - forkast.news
    Aug 30, 2026 20:34

    news.google.com ยท Data Leak

  • Latest observed development
    Aug 30, 2026 20:34

    Most recent source or update associated with this incident.

Sources

ServiceNow patches critical AI platform flaw that could allow user impersonation - CyberScoop

cyberscoop.com ยท Jan 13, 2026 05:30

A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.

Open publisher source
ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation - The Hacker News

thehackernews.com ยท Jan 13, 2026 05:30

ServiceNow patched CVE-2025-12420, codenamed BodySnatcher, a critical vulnerability (CVSS 9.3) in its AI Platform that allowed unauthenticated user impersonation. This flaw enabled attackers to bypass MFA/SSO by chaining a hardcoded secret with email-based account linking, facilitating arbitrary actions and potential privilege escalation.

Open publisher source
ServiceNow patches critical AI Platform vulnerability enabling user impersonation - SC Media

scworld.com ยท Jan 15, 2026 05:30

ServiceNow has patched CVE-2025-12420, dubbed "BodySnatcher," a critical AI Platform vulnerability with a CVSS score of 9.3. This flaw allowed unauthenticated attackers to impersonate users and execute arbitrary actions within affected Now Assist AI Agents and Virtual Agent APIs.

Open publisher source
CLOP Is Mass-Exploiting PTC Windchill at Scale. Every AI Agent Connected to It Inherits the Breach. - forkast.news

news.google.com ยท Aug 30, 2026 20:34

CLOP Is Mass-Exploiting PTC Windchill at Scale. Every AI Agent Connected to It Inherits the Breach. forkast.news

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence