The news
Security firm Zenity Labs on September 24 detailed three Salesforce Agentforce flaws, dubbed SalesBleed, that could have let outsiders pull customer relationship management (CRM) data from Salesforce (CRM) with zero clicks and misuse its AI agent for Slack phishing. Zenity says Salesforce has since fixed all three.
Agentforce is Salesforce's platform for AI agents that answer questions and take actions inside its CRM. According to Zenity, the attack started with Web-to-Lead, the public forms companies put on websites to capture sales inquiries. An attacker could submit a lead containing hidden instructions, a technique known as indirect prompt injection. The instructions sat dormant until an employee asked the agent a routine question such as checking the latest leads.
At that point, Zenity said, the agent followed the planted instructions, queried the Accounts table and embedded the results in an image link or Slack URL. When rendered, the link triggered a DNS lookup to an attacker-controlled server, carrying the stolen data in the web address. The proof of concept pulled company names and deal sizes. Zenity said no privilege escalation was needed, because the default General CRM subagent could already read both leads and accounts.
The exfiltration worked because Zenity bypassed Agentforce's Trusted URLs feature, which is meant to strip untrusted links from agent responses. The researchers said unfamiliar top-level domains such as .fun were not recognized as web addresses, and characters such as curly braces caused the filter and the browser to disagree about where a link ended.
The third flaw involved the Reply to a Slack Thread action in the default Slack Knowledge subagent. Zenity said it lacked both user confirmation before sending and attribution showing who triggered it, so an insider or an outside attacker using a poisoned lead could make the agent post phishing links to Slack channels. Zenity reported the issues on June 1. It said it verified Salesforce's fix for the Trusted URLs bypass on August 19 and, on September 21, confirmed after testing that all three flaws were fixed. The fix confirmations come from Zenity; neither its posts nor The Register's report included a statement from Salesforce, and none of them said whether the flaws had been exploited outside the research.
The numbers
- Flaws disclosed
- 3
- Date reported to Salesforce
- June 1, 2026
- Date Zenity confirmed all fixes
- September 21, 2026
- Date research published
- September 24, 2026
Why CEOs should care
For CISOs, SalesBleed is a clear example of the core AI agent risk: any agent that reads outside data can be steered by it. Web forms, emails, support tickets and documents all carry text written by strangers. Security teams should map which agents read external input, what data each can query, and whether agent responses can contain links or images that reach the internet. Reducing default permissions, such as a general CRM agent's read access to all accounts, limits what a hijacked agent can leak.
Zenity also warned that write actions can be reconfigured easily; it said a single click can disable user confirmation protections. Salesforce administrators should review which Agentforce actions can send messages or change records, confirm that user approval is required for sensitive actions, and ensure that messages sent by agents show which person triggered them.
For buyers and boards, the lesson is to ask AI vendors specific questions before expanding agent deployments: how they detect prompt injection, how they filter outbound links, how quickly they fix reported flaws, and whether they notify customers. By Zenity's timeline, Salesforce took from June to September to close all three issues, a reminder that agent security depends on vendor processes as much as on customer settings.
The bigger picture
Enterprise software vendors are racing to embed AI agents in CRM, collaboration and IT tools, and researchers keep finding that agents can be tricked into acting against their owners. Zenity co-founder and chief technology officer Michael Bargury told The Register that as agents grow more capable, “a single overlooked gap can change everything.”
The Slack element matters because messages from a trusted internal bot carry more credibility than an outside email, which makes agent-sent phishing harder for staff to spot.
What’s next
Watch for Salesforce guidance to Agentforce customers on configuration hardening, and for similar research targeting other vendors' agent platforms. Companies using Agentforce should confirm their settings match Salesforce's current defaults and review logs, as far back as retention allows, for unusual agent queries or outbound links.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








