Improper authentication in Now Assist AI Agents and Virtual Agent API - CVE-2025-12420

 

Improper authentication in Now Assist AI Agents and Virtual Agent API - CVE-2025-12420

Published: January 13, 2026


Vulnerability identifier: #VU121325
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12420
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the authentication requests. A remote non-authenticated attacker can impersonate any platform user and gain unauthorized access to the application with privileges of the impersonated user.


Affected software

Now Assist AI Agents
Virtual Agent API

How to mitigate CVE-2025-12420

Install updates from vendor's website.

Now Assist AI Agents - addressed in versions 5.1.18, 5.2.19
Virtual Agent API - addressed in versions 3.15.2, 4.0.4

External References

Related Security Bulletins