Agentic Hijacking Vulnerability in ServiceNow - https://appomni.com/ao-labs/bodysnatc...
Imagine an unauthenticated attacker who has never logged into your ServiceNow instance and has no credentials, and is sitting halfway across the globe. With only a target’s email address, the attacker can impersonate an administrator and execute an AI agent to override security controls and create backdoor accounts with full privileges.
This could grant nearly unlimited access to everything an organization houses, such as customer Social Security numbers, healthcare information, financial records, or confidential intellectual property.
#Bodysnatcher #BodysnatcherAI #ServiceNow #ServiceNowSecurity #AgenticAI #AIAgents #AISecurity #Vulnerability #CVE #CVE2025 #CloudSecurity #SaaSSecurity #IdentitySecurity #AppSec #ThreatResearch #SOC #AISECHUB #ServiceNow #appomni