SalesBleed: Salesforce Agentforce Flaws Expose CRM Data Without a Click
“SalesBleed” Exploits Salesforce AI Agents for Zero-Click Data Theft
A newly disclosed set of vulnerabilities dubbed “SalesBleed” affected Salesforce Agentforce, demonstrating how an attacker could manipulate trusted AI agents to exfiltrate CRM data without a victim clicking a malicious link and potentially use those agents to conduct phishing through internal Slack channels. Researchers at Zenity Labs disclosed the findings on September 24, 2026.
How SalesBleed Worked
SalesBleed consists of three vulnerabilities involving Agentforce. Two could enable zero-click data exfiltration, while the third could allow an attacker to abuse an Agentforce-Slack integration to distribute phishing messages.
The attack began with a surprisingly ordinary entry point: a public Salesforce Web-to-Lead form.
An attacker could:
- Submit a poisoned sales lead containing malicious AI instructions through a public Web-to-Lead form. No Salesforce authentication was required.
- The malicious instructions would remain stored inside the CRM until an employee later asked Agentforce to process or review the affected lead.
- Agentforce could interpret the externally supplied content as instructions, creating an indirect prompt-injection attack.
- Because the Agentforce component already possessed legitimate CRM permissions, the injected instructions could cause it to retrieve information from other CRM records.
- Researchers demonstrated methods that could transmit CRM information externally while circumventing protections intended to restrict untrusted URLs. The employee did not need to click a malicious URL or approve the operation, resulting in the zero-click characterization.
The Slack Phishing Risk
Researchers also found that the Slack integration could extend the attack beyond data theft. A poisoned lead could manipulate an Agentforce agent into posting messages to internal Slack channels using the trusted agent's identity.
That creates a particularly concerning social-engineering scenario because employees could see a malicious message originating inside a trusted corporate collaboration environment rather than arriving through external email.
Has It Been Fixed?
Yes, according to the available disclosures. Salesforce worked with Zenity Labs to address the vulnerabilities, and reporting indicates the demonstrated SalesBleed attack chains no longer work. Infosecurity Magazine reports that Salesforce fully remediated the URL-redaction bypass on August 18, 2026, before public disclosure in September.
Why SalesBleed Matters
The larger lesson is bigger than Salesforce. SalesBleed demonstrates a significant security problem emerging with agentic AI:
Untrusted external data can become instructions when an AI agent processes it, while the agent may simultaneously possess trusted access to sensitive corporate systems.Traditional application security generally attempts to separate data from executable instructions. Agentic AI complicates that boundary because natural-language content can simultaneously look like business data to an application and an instruction to an AI model. SalesBleed demonstrates how that combination can potentially connect a public Internet-facing input, an AI agent with privileged CRM access, and an internal communications platform.
Recommended Defensive Actions
For organizations using Salesforce Agentforce, I would prioritize:
- Confirm Salesforce's SalesBleed remediation is present in the organization's Agentforce environment.
- Inventory Agentforce agents and their permissions, particularly agents able to query sensitive CRM objects.
- Apply least privilege to AI agents rather than allowing broad access simply because the underlying user has that access.
- Treat Web-to-Lead and other Internet-originated CRM information as untrusted input, even after it has entered Salesforce.
- Review Agentforce integrations with Slack and other collaboration platforms.
- Monitor unusual agent-initiated queries, external URL activity, and unexpected messages generated through AI identities.
- Consider prompt injection an application-security threat, not merely an AI accuracy problem.
- Include AI agents in incident-response, data-loss-prevention, and security-monitoring strategies.
Bottom line: SalesBleed is important because attackers did not need to compromise a Salesforce account first. The research showed how malicious instructions could be planted through a legitimate public business workflow and later executed indirectly by a trusted AI agent with access to sensitive enterprise information.
Possible headline:

Comments
Post a Comment