Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Salesforce Agentforce flaws could have let attackers pull CRM data with zero clicks, Zenity says

Researchers showed that a malicious sales lead could plant instructions an AI agent later obeyed, sending account data to an outside server. Zenity says Salesforce has fixed all three issues.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Zenity Labs disclosed three Agentforce flaws, dubbed SalesBleed, on September 24; Zenity said it confirmed on September 21 that Salesforce had fixed all three.
  • 2A poisoned Web-to-Lead form entry could make an agent leak CRM data such as company names and deal sizes without clicks.
  • 3A Slack reply action lacked confirmation and attribution, letting the agent post phishing messages under its own trusted identity.

The news

Security firm Zenity Labs on September 24 detailed three Salesforce Agentforce flaws, dubbed SalesBleed, that could have let outsiders pull customer relationship management (CRM) data from Salesforce (CRM) with zero clicks and misuse its AI agent for Slack phishing. Zenity says Salesforce has since fixed all three.

Agentforce is Salesforce's platform for AI agents that answer questions and take actions inside its CRM. According to Zenity, the attack started with Web-to-Lead, the public forms companies put on websites to capture sales inquiries. An attacker could submit a lead containing hidden instructions, a technique known as indirect prompt injection. The instructions sat dormant until an employee asked the agent a routine question such as checking the latest leads.

At that point, Zenity said, the agent followed the planted instructions, queried the Accounts table and embedded the results in an image link or Slack URL. When rendered, the link triggered a DNS lookup to an attacker-controlled server, carrying the stolen data in the web address. The proof of concept pulled company names and deal sizes. Zenity said no privilege escalation was needed, because the default General CRM subagent could already read both leads and accounts.

The exfiltration worked because Zenity bypassed Agentforce's Trusted URLs feature, which is meant to strip untrusted links from agent responses. The researchers said unfamiliar top-level domains such as .fun were not recognized as web addresses, and characters such as curly braces caused the filter and the browser to disagree about where a link ended.

The third flaw involved the Reply to a Slack Thread action in the default Slack Knowledge subagent. Zenity said it lacked both user confirmation before sending and attribution showing who triggered it, so an insider or an outside attacker using a poisoned lead could make the agent post phishing links to Slack channels. Zenity reported the issues on June 1. It said it verified Salesforce's fix for the Trusted URLs bypass on August 19 and, on September 21, confirmed after testing that all three flaws were fixed. The fix confirmations come from Zenity; neither its posts nor The Register's report included a statement from Salesforce, and none of them said whether the flaws had been exploited outside the research.

The numbers

Flaws disclosed
3
Date reported to Salesforce
June 1, 2026
Date Zenity confirmed all fixes
September 21, 2026
Date research published
September 24, 2026

Why CEOs should care

For CISOs, SalesBleed is a clear example of the core AI agent risk: any agent that reads outside data can be steered by it. Web forms, emails, support tickets and documents all carry text written by strangers. Security teams should map which agents read external input, what data each can query, and whether agent responses can contain links or images that reach the internet. Reducing default permissions, such as a general CRM agent's read access to all accounts, limits what a hijacked agent can leak.

Zenity also warned that write actions can be reconfigured easily; it said a single click can disable user confirmation protections. Salesforce administrators should review which Agentforce actions can send messages or change records, confirm that user approval is required for sensitive actions, and ensure that messages sent by agents show which person triggered them.

For buyers and boards, the lesson is to ask AI vendors specific questions before expanding agent deployments: how they detect prompt injection, how they filter outbound links, how quickly they fix reported flaws, and whether they notify customers. By Zenity's timeline, Salesforce took from June to September to close all three issues, a reminder that agent security depends on vendor processes as much as on customer settings.

The bigger picture

Enterprise software vendors are racing to embed AI agents in CRM, collaboration and IT tools, and researchers keep finding that agents can be tricked into acting against their owners. Zenity co-founder and chief technology officer Michael Bargury told The Register that as agents grow more capable, “a single overlooked gap can change everything.”

The Slack element matters because messages from a trusted internal bot carry more credibility than an outside email, which makes agent-sent phishing harder for staff to spot.

What’s next

Watch for Salesforce guidance to Agentforce customers on configuration hardening, and for similar research targeting other vendors' agent platforms. Companies using Agentforce should confirm their settings match Salesforce's current defaults and review logs, as far back as retention allows, for unusual agent queries or outbound links.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

SalesforceZenityAI agentsPrompt injection

Earlier coverage of Salesforce

All Salesforce coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.