‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce, collectively dubbed 'SalesBleed,' allowed attackers to hijack trusted agents, exfiltrate sensitive CRM data without user interaction, and conduct phishing attacks via Slack. The flaws exploited weaknesses in the Trusted URLs mechanism and the Agentforce-Slack integration, enabling zero-click data exfiltration and unauthorized message posting. Salesforce confirmed these vulnerabilities were fixed by August 19, 2026.
AI Analysis
Technical Summary
SalesBleed consists of three vulnerabilities in Salesforce Agentforce discovered by Zenity Labs. Two flaws stem from weaknesses in the Trusted URLs security mechanism, which failed to properly validate top-level domains and URL parsing, allowing malicious Web-to-Lead form payloads to trigger zero-click exfiltration of CRM data to attacker-controlled servers. The third vulnerability involves the Agentforce-Slack integration, where specially crafted links in Slack cause automatic requests leaking CRM data and enable attackers to hijack the Agentforce agent to send phishing messages to internal Slack channels. These phishing messages appear to come from a trusted internal system, increasing the likelihood of credential theft. Salesforce confirmed all three vulnerabilities were addressed by August 19, 2026.
Potential Impact
Attackers could hijack trusted Agentforce agents to exfiltrate sensitive CRM data without user interaction (zero-click), bypassing security policies. The flaws also allowed attackers to weaponize the Agentforce agent to send phishing messages within Slack channels, impersonating trusted internal systems. Successful phishing could lead to credential compromise and further access to enterprise resources such as email, Slack, and source code repositories.
Mitigation Recommendations
Salesforce confirmed that all three SalesBleed vulnerabilities were fixed by August 19, 2026. Organizations using Salesforce Agentforce should ensure they have applied the official patches or updates released by Salesforce. No additional mitigation actions are required beyond applying these fixes.
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Description
Three vulnerabilities in Salesforce Agentforce, collectively dubbed 'SalesBleed,' allowed attackers to hijack trusted agents, exfiltrate sensitive CRM data without user interaction, and conduct phishing attacks via Slack. The flaws exploited weaknesses in the Trusted URLs mechanism and the Agentforce-Slack integration, enabling zero-click data exfiltration and unauthorized message posting. Salesforce confirmed these vulnerabilities were fixed by August 19, 2026.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SalesBleed consists of three vulnerabilities in Salesforce Agentforce discovered by Zenity Labs. Two flaws stem from weaknesses in the Trusted URLs security mechanism, which failed to properly validate top-level domains and URL parsing, allowing malicious Web-to-Lead form payloads to trigger zero-click exfiltration of CRM data to attacker-controlled servers. The third vulnerability involves the Agentforce-Slack integration, where specially crafted links in Slack cause automatic requests leaking CRM data and enable attackers to hijack the Agentforce agent to send phishing messages to internal Slack channels. These phishing messages appear to come from a trusted internal system, increasing the likelihood of credential theft. Salesforce confirmed all three vulnerabilities were addressed by August 19, 2026.
Potential Impact
Attackers could hijack trusted Agentforce agents to exfiltrate sensitive CRM data without user interaction (zero-click), bypassing security policies. The flaws also allowed attackers to weaponize the Agentforce agent to send phishing messages within Slack channels, impersonating trusted internal systems. Successful phishing could lead to credential compromise and further access to enterprise resources such as email, Slack, and source code repositories.
Mitigation Recommendations
Salesforce confirmed that all three SalesBleed vulnerabilities were fixed by August 19, 2026. Organizations using Salesforce Agentforce should ensure they have applied the official patches or updates released by Salesforce. No additional mitigation actions are required beyond applying these fixes.
Technical Details
- Classification
- {"confidence":0.86,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/","fetched":true,"fetchedAt":"2026-09-25T09:32:48.116Z","wordCount":1100}
Threat ID: 6ab63fc0f7a7c5410699edcf
Added to database: 09/25/2026, 09:32:48 UTC
Last enriched: 09/25/2026, 09:32:54 UTC
Last updated: 09/25/2026, 14:12:27 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.