Back Securityweek 'SalesBleed' Flaws in Salesforce Agentforce Enabled Zero
Three vulnerabilities in Salesforce Agentforce could have allowed attackers to hijack trusted agents for sensitive CRM data exfiltration and phishing, Zenity Labs reports.
Dubbed SalesBleed , the flaws could be exploited via Web-to-Lead forms, Salesforce’s official lead-collection mechanism, which also provides a direct path to the CRM.
Malicious instructions injected into a Web-to-Lead lead would remain dormant until an employee asks an Agentforce agent to interact with the submission, causing the agent to process the poisoned lead and execute the hidden instructions.
According to Zenity Labs, two of the SalesBleed bugs could be exploited in zero-click data exfiltration attacks, while the third allowed attackers to weaponize an Agentforce agent to distribute phishing messages.
The first two flaws were caused by multiple weaknesses in Trusted URLs, the security mechanism designed to block Agentforce from displaying URLs and images from untrusted sources. The third affects the Agentforce-Slack integration.
Zenity Labs discovered that a Web-to-Lead form payload could be used to access leads and accounts table data and then use HTML image tags for zero-click CRM data exfiltration to the attacker’s server.
“Agentforce reported that the content had been blocked by the organization’s security policies, even though the sensitive CRM data had already been transmitted to the attacker-controlled server,” the company notes.
While Trusted URLs should prevent Agentforce from accessing and sending data to unapproved domains, Zenity Labs discovered that the mechanism did not recognize top-level domains and that character sequences could tamper with URL parsing.
Using the same poisoned Web-to-Lead mechanism, an attacker could interact with the Agentforce agent via Slack, which automatically retrieves link information for previews.
“Specially constructed links can cause Slack to initiate requests that carry CRM data to attacker-controlled infrastructure as soon as the links appear,” Zenity Labs says.
Additionally, the cybersecurity firm discovered that Agentforce’s integration with Slack could be abused to turn the AI agents into a social-engineering mechanism and send messages to various internal Slack channels.
Because the agent did not identify the user sending the message, an attacker could use a malicious Web-to-Lead to hijack the agent and post phishing messages to Slack using the agent’s identity.
“Employees receive a message from a trusted system already operating inside their workplace rather than from an unfamiliar outside sender. Users who follow the phishing link and surrender their credentials could give attackers access to email, Slack, source code repositories and other enterprise applications available through the compromised identity, Zenity Labs notes.
The cybersecurity firm reported the SalesBleed vulnerabilities on June 1, and Salesforce confirmed that all three bugs had been addressed by August 19.
Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Related: Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Related: AI-Powered Campaign Targets Hundreds of Online Retailers
Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.
Artificial Intelligence
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high...
Artificial Intelligence
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions.
Artificial Intelligence
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.
Artificial Intelligence
AI-Powered Campaign Targets Hundreds of Online Retailers
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.
Artificial Intelligence
Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking fixing known problems, not judgment calls unfamiliar risk.
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
