Back Infosecurity-Magazine Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
Security researchers at Zenity Labs have disclosed a set of zero-click vulnerabilities in Salesforce Agentforce that allowed attackers to silently exfiltrate sensitive data related to customer relationship management (CRM) without any interaction from the victim and without the attacker ever authenticating into the target's Salesforce environment.
The findings, published September 24by Zenity’s threat research team, detail an attack chain dubbed ‘SalesBleed.’
According to the report , attackers could plant hidden prompt injection payloads inside public-facing Web-to-Lead forms, a standard Salesforce feature that allows external users to submit data that flows directly into CRM records.
When an Agentforce agent later processed that record as part of normal business operations, the embedded instructions would hijack the agent's behavior.
The attack chain combined three elements:
Prompt injection via Web-to-Lead forms providing the agent with the ability to ingest untrusted external input
Agent trusting record content as instructions: the agent is allowed render links or images back to a user interface
Agent’s underlying access to sensitive tool and data permissions
Once triggered, the injected payload could instruct the agent to quietly query and exfiltrate sensitive account data, including company names, deal sizes and other CRM fields, using DNS-based exfiltration techniques that evaded Salesforce's Trusted URLs redaction controls, a safeguard designed to prevent exactly this kind of data leakage through outbound links.
Critically, the attacker could perform a successful compromise without direct access to the target organization and the attack required no click or credential theft. The lead submission alone was enough to seed the payload, and normal agent operation did the rest.
Zenity reported the vulnerabilities to Salesforce in June, and Salesforce fully fixed the URL redaction bypass, which remediated the issues, on August 18.
Untrusted CRM Content Can Turn AI Agents Into Data-Exfiltration Paths
While the specific vulnerabilities in SalesBleed have been fixed, the Zenity researchers emphasized that the underlying risk pattern is not unique to Agentforce.
Any AI agent that reads or processes records submitted by external, untrusted sources, renders links, images, or other rich content back to users, and holds tool access to sensitive backend data “has the same three ingredients sitting in the same place,” creating a latent path for prompt injection-driven exfiltration.
“Our payload asked for company names and deal sizes, but the injection could have asked for anything the subagent's Query Records tool can reach (which can include sensitive data). In a typical General CRM deployment, that includes accounts, contacts, and more,” the Zenity report noted.
Image credits: bluestork /JHVEPhoto / Shutterstock.com
New Zero-Click Flaw in Claude Desktop Extensions, Anthropic Declines Fix News 9 February 2026
New Zero-Click Flaw in Claude Desktop Extensions, Anthropic Declines Fix
Google Makes CodeMender Available as Managed AI Security Agent News 22 July 2026
Google Makes CodeMender Available as Managed AI Security Agent
OpenAI Expands Bug Bounty to Cover AI Abuse and 'Safety' Concerns News 26 March 2026
OpenAI Expands Bug Bounty to Cover AI Abuse and 'Safety' Concerns
OpenAI Launches 'Daybreak' to Help Build Secure By Design Software News 12 May 2026
OpenAI Launches 'Daybreak' to Help Build Secure By Design Software
What CISOs Should Know (And Do) OpenClaw News Feature 13 March 2026
What CISOs Should Know (And Do) OpenClaw
What’s Hot on Infosecurity Magazine?
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
Ransomware Attacks Reach Record High for 2026
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
Hundreds of Leaked GitHub App Keys Still Authenticate
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
From APIs to Agents: How to Secure AI at Enterprise Scale
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
How To Enhance Security Operations with AI-Powered Defenses
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
