An AI sales agent that quietly reads a form submission and hands your customer database to a stranger is not a hypothetical anymore. Researchers have disclosed a trio of vulnerabilities in Salesforce’s Agentforce platform, collectively nicknamed “SalesBleed,” that let attackers pull sensitive CRM records out of a company’s Salesforce instance without the victim ever clicking a link, opening an attachment, or doing anything that looked remotely suspicious. The flaws are already fixed, but the mechanics behind them say a lot about where enterprise AI security is headed next.
What SalesBleed Actually Is
SalesBleed isn’t one bug. It’s a set of three separate weaknesses in Agentforce, the AI agent layer Salesforce has built directly into its CRM so employees can ask an assistant to summarize leads, draft follow-ups, and generally do busywork on their behalf. Two of the three flaws exploited gaps in a feature called “Trusted URLs,” which exists specifically to stop AI agents from fetching or sending data to destinations that haven’t been explicitly approved. The third flaw lived in the connection between Agentforce and Slack, letting an attacker essentially borrow the agent’s identity to send messages that looked like they came from a trusted internal bot.
The name is a nod to how the attack behaves: data quietly drains out of the CRM the moment an AI agent touches a poisoned record, with no visible trigger on the victim’s end.
Who Found It, and When
Agentic AI security firm Zenity Labs discovered and reported the vulnerabilities to Salesforce on June 1, 2026. Salesforce confirmed all three issues were patched by August 19, 2026, meaning the holes were already closed by the time details became public. That’s the pattern researchers generally want to see: report privately, give the vendor time to fix it, disclose after the fact. Still, the gap between discovery and patch means the flaws were live in production Salesforce environments for roughly eleven weeks.
How the Attack Chain Actually Worked
What makes SalesBleed worth understanding isn’t just that it existed — it’s how mundane the entry point was. The attacker didn’t need credentials, a phishing email, or any kind of network access. They used a feature every Salesforce customer already has turned on.
- Step one: Salesforce’s Web-to-Lead forms let anyone submit a sales inquiry straight into a company’s CRM from a public website, no login required. That’s by design — it’s how businesses capture prospective customers.
- Step two: An attacker fills out that public form, but buries hidden instructions inside the text fields — a prompt injection payload disguised as an ordinary inquiry.
- Step three: The poisoned lead just sits in the CRM. Nothing happens. It’s inert data until someone interacts with it.
- Step four: An employee, doing completely normal work, asks their Agentforce AI agent to review, summarize, or process the new lead.
- Step five: The agent reads the lead — and reads the attacker’s hidden instructions right along with it, because the model has no reliable way to tell “data I’m summarizing” apart from “commands I’m supposed to follow.”
- Step six: The agent executes those instructions, triggering data exfiltration or firing off a phishing attempt, all without the employee clicking anything or noticing anything unusual.
That last part is the “zero-click” element security teams should sit with. The victim’s entire contribution to the breach was asking their AI assistant to do its job.
The Exfiltration Trick — and a Nasty Bit of False Reassurance
The first two flaws gave attackers access to data sitting in the CRM’s leads and accounts tables — the kind of records that include names, contact details, deal notes, and internal account context. To get that data out, the injected instructions used an old but effective trick: embedding the stolen information inside an HTML image tag. When that tag tries to “load” its image, it’s actually sending a web request to a server the attacker controls, with the sensitive data tucked into the request itself. No malware, no obvious network anomaly — just an image that never needed to exist.
Zenity Labs flagged a particularly unsettling detail here. Agentforce’s own security guardrails would sometimes tell the user that content had been “blocked by the organization’s security policies” — a message clearly meant to reassure. Except by the time that message appeared, the sensitive CRM data had already been silently sent to the attacker’s server. The warning wasn’t wrong that a policy had triggered; it just showed up after the damage was done, giving victims a false sense that the system had caught the problem.
The Slack Angle
The third vulnerability took a different route. Because Agentforce is wired into Slack for many organizations, attackers who exploited this flaw could hijack the agent’s identity and post phishing messages directly into company Slack channels — messages that appeared to come from the trusted internal AI bot rather than an outside party. That distinction matters more than it might seem. Employees have learned to be wary of external senders, but a message from a bot they use every day, inside a tool they already trust, sails right past that instinct.
Why This Isn’t Just a Salesforce Problem
SalesBleed is a clean example of a pattern security researchers have been warning about all through 2026: the “lethal trifecta.” An AI agent becomes dangerous when it has three things at once — the ability to read untrusted external input, access to private internal data, and the ability to communicate or take action outside the system. Web-to-Lead forms supplied the untrusted input. The CRM supplied the private data. Slack and outbound web requests supplied the exit route. Take away any one leg of that triangle and the attack collapses.
This is the uncomfortable part of wiring AI agents directly into business systems. The functionality that makes Agentforce useful — reading incoming leads and acting on them without a human re-typing everything — is the exact same functionality that made this attack possible. That tension isn’t unique to Salesforce. Any platform that lets an AI agent ingest public-facing content and then act on internal systems with real permissions is sitting on the same structural risk, whether the product is a CRM, a support desk, or an internal knowledge base.
| Flaw | Component Affected | Impact |
|---|---|---|
| Flaw 1 | Trusted URLs mechanism | Exfiltration of leads/accounts data via image-tag trick |
| Flaw 2 | Trusted URLs mechanism | Bypass of outbound data-blocking protections |
| Flaw 3 | Agentforce–Slack integration | Identity hijack enabling internal phishing |
What This Means
The good news is straightforward: all three SalesBleed vulnerabilities are patched, and there’s no indication they were exploited in the wild before Zenity Labs reported them. Salesforce customers running current versions of Agentforce aren’t exposed to this specific chain anymore.
The bigger takeaway is less tidy. SalesBleed didn’t require a sophisticated exploit or a coding flaw in the traditional sense — it required an AI agent doing exactly what it was designed to do, reading text it was given and acting on it. Prompt injection keeps showing up in enterprise AI incidents this year precisely because it doesn’t need a technical vulnerability to work; it just needs an agent that can’t tell data from instructions. Until AI platforms build a real, durable separation between the two, any system that lets an agent read public input and touch private data is a candidate for the next version of this story. Security teams evaluating AI agent deployments would do well to ask a blunt question before rollout: what happens if the first thing this agent reads is malicious? SalesBleed is the answer for Salesforce. It won’t be the last time someone has to answer it for a different platform.




