This is a paid press release. Contact the press release distributor directly with any inquiries.
Zenity Labs Uncovers SalesBleed, 3 Salesforce Agentforce Flaws Enabling Zero-Click CRM Data Theft and AI Agent Impersonation
Flaws allow attackers to silently extract sensitive Salesforce data and abuse trusted enterprise AI agents for phishing
NEW YORK, September 24, 2026–(BUSINESS WIRE)–Zenity Labs today disclosed SalesBleed, a set of three security vulnerabilities in Salesforce Agentforce that could allow a single untrusted lead to hijack trusted Agentforce agents, silently exfiltrate sensitive CRM data and turn an enterprise agent into a vehicle for delivering elaborate phishing attacks.
Two of the vulnerabilities enable zero-click data exfiltration, allowing sensitive Salesforce data to be transmitted to attacker-controlled infrastructure without requiring an employee to click or approve anything. The third allows attackers to weaponize the trusted identity of an Agentforce-connected Slack agent to distribute phishing messages to employees from inside the enterprise.
Zenity Labs found multiple weaknesses in Trusted URLs, the Salesforce security mechanism designed to prevent Agentforce from displaying URLs and images from untrusted sources. The researchers demonstrated that those weaknesses could be abused to send sensitive data to unapproved destinations. The research also uncovered a separate flaw in the Agentforce-Slack integration that allowed the trusted identity of an enterprise AI agent to be abused for phishing.
Zenity Labs responsibly disclosed the findings to Salesforce, which worked with the researchers to investigate and remediate the reported issues.
“This isn’t one clever bypass or a single misconfiguration. We found multiple ways to break through the security boundary designed to stop Agentforce from sending enterprise data to unapproved destinations,” said Michael Bargury, co-founder and CTO of Zenity. “Hard boundaries remain one of the strongest tools we have for containing AI agents, but they are still software. When those controls fail, we are left with a privileged access agent with high autonomy and no bounds.”
One Public Form Can Start the Attack
One attack chain begins with nothing more than a Web-to-Lead form. Web-to-Lead is Salesforce’s official mechanism for collecting leads and creates a direct path for outside information to enter the Salesforce CRM. As Zenity Labs demonstrated at Black Hat 2025, when Agentforce processes that information, the same pathway can become an attack vector. Attackers can plant malicious instructions in a Web-to-Lead submission that remain dormant until an employee later asks an Agentforce agent an ordinary question about leads. Once the agent processes the poisoned lead, the hidden instructions can hijack its behavior, causing it to exfiltrate sensitive Salesforce data or take other attacker-directed actions while returning what appears to be a normal response to the employee.