Back to Feed
VulnerabilitiesSep 25, 2026

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Salesforce Agentforce had 'SalesBleed' flaws enabling zero-click data exfiltration and phishing.

Summary

Three 'SalesBleed' vulnerabilities in Salesforce Agentforce allowed attackers to hijack trusted agents for data exfiltration and phishing attacks. Exploitable via Web-to-Lead forms, two flaws enabled zero-click data theft by bypassing Trusted URLs, while the third weaponized the Agentforce-Slack integration for phishing. Salesforce has since patched these issues.

Full text

Three vulnerabilities in Salesforce Agentforce could have allowed attackers to hijack trusted agents for sensitive CRM data exfiltration and phishing, Zenity Labs reports. Dubbed SalesBleed, the flaws could be exploited via Web-to-Lead forms, Salesforce’s official lead-collection mechanism, which also provides a direct path to the CRM. Malicious instructions injected into a Web-to-Lead lead would remain dormant until an employee asks an Agentforce agent to interact with the submission, causing the agent to process the poisoned lead and execute the hidden instructions. According to Zenity Labs, two of the SalesBleed bugs could be exploited in zero-click data exfiltration attacks, while the third allowed attackers to weaponize an Agentforce agent to distribute phishing messages. The first two flaws were caused by multiple weaknesses in Trusted URLs, the security mechanism designed to block Agentforce from displaying URLs and images from untrusted sources. The third affects the Agentforce-Slack integration. Zenity Labs discovered that a Web-to-Lead form payload could be used to access leads and accounts table data and then use HTML image tags for zero-click CRM data exfiltration to the attacker’s server.Advertisement. Scroll to continue reading. “Agentforce reported that the content had been blocked by the organization’s security policies, even though the sensitive CRM data had already been transmitted to the attacker-controlled server,” the company notes. While Trusted URLs should prevent Agentforce from accessing and sending data to unapproved domains, Zenity Labs discovered that the mechanism did not recognize top-level domains and that character sequences could tamper with URL parsing. Using the same poisoned Web-to-Lead mechanism, an attacker could interact with the Agentforce agent via Slack, which automatically retrieves link information for previews. “Specially constructed links can cause Slack to initiate requests that carry CRM data to attacker-controlled infrastructure as soon as the links appear,” Zenity Labs says. Additionally, the cybersecurity firm discovered that Agentforce’s integration with Slack could be abused to turn the AI agents into a social-engineering mechanism and send messages to various internal Slack channels. Because the agent did not identify the user sending the message, an attacker could use a malicious Web-to-Lead to hijack the agent and post phishing messages to Slack using the agent’s identity. “Employees receive a message from a trusted system already operating inside their workplace rather than from an unfamiliar outside sender. Users who follow the phishing link and surrender their credentials could give attackers access to email, Slack, source code repositories and other enterprise applications available through the compromised identity, Zenity Labs notes. The cybersecurity firm reported the SalesBleed vulnerabilities on June 1, and Salesforce confirmed that all three bugs had been addressed by August 19. Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs Related: Autonomous AI Hacks Raise Thorny Questions of Legal Accountability Related: AI-Powered Campaign Targets Hundreds of Online Retailers Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire SolarWinds Patches Critical RCE Flaws in Observability Self-HostedAstrana Health Data Breach Impacts Private, Confidential InformationCritical WordPress Vulnerability Exploited Immediately After DisclosureAdobe Patches Critical Flaws in Connect, AEM FormsChrome 154 Patches 108 VulnerabilitiesArista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayCheck Point Patches Exploited Management Server Zero-Day Latest News Roundcube Webmail Vulnerability in Attackers’ CrosshairsAutonomous AI Hacks Raise Thorny Questions of Legal AccountabilityKontext Security Emerges With $4 Million for AI Agent Runtime ControlsOpenAI Agents Probed Websites for Vulnerabilities While Fetching Public DataAI-Powered Campaign Targets Hundreds of Online RetailersIsland Raises $400 Million at $6.4 Billion ValuationOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsBegin at the End: How to Enable Agentic Remediation Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Agentforce (product)Salesforce (vendor)Web-to-Lead (product)Slack (product)CRM (product)