What happened
Zenity Labs disclosed on 2026-09-24 a three-flaw zero-click chain ('SalesBleed') in Salesforce Agentforce: prompt injection via public Web-to-Lead forms, agent trust of record content as instructions, and broad Query Records tool access — enabling silent CRM data exfiltration (company names, deal sizes, arbitrary account fields) via DNS and Slack link-preview channels with no click or credential theft. Salesforce shipped fixes in August.
Why it matters
SalesBleed is the canonical 'agent as data-exfiltration path' incident of the window: a fully untrusted external input (a web form) plus an autonomous agent's legitimate permissions equals silent data theft that even the platform's own policy controls reported as blocked only after data had already left. It demonstrates that indirect prompt-injection chains remain exploitable in the biggest enterprise agent deployment (Agentforce) and that no-CVE/non-model-level vulnerabilities drive agent risk.
Attack vector
An attacker submits a lead with a hidden prompt injection in a form field; when an employee later asks the Agentforce agent about leads, the agent treats the field as instructions, queries the Accounts table via its Query Records tool, and exfiltrates fields encoded into an attacker-controlled hostname rendered as an HTML img/URL — leaking data out-of-band via DNS and Slack link previews, bypassing Salesforce Trusted-URL redaction.
Affected systems
Salesforce Agentforce (General CRM subagent); no CVE assigned; fixed by Salesforce Aug 18-19, 2026
Mitigation
Salesforce fixed the URL redaction bypass (RFC 3986 parsing) on Aug 18-19; patched. Defenders with any agent combining untrusted record input + broad data tools + rich content rendering should apply the same controls. Primary: Zenity Labs disclosure (2026-09-24), https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/ and https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958