DKDKCISSPSearch
AI Security

Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk

The findings, published September 24by Zenity’s threat research team, detail an attack chain dubbed ‘SalesBleed.’ According to the report , attackers could plant hidden prompt injection payloads inside public-facing Web-to-Lead forms, a standard Salesforce feature that allows external users to submit data that flows directly into CRM records.

DKCISSP News DeskInfosecurity Magazine25 Sept 2026, 7:00 pm
Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

The findings, published September 24by Zenity’s threat research team, detail an attack chain dubbed ‘SalesBleed.’ According to the report , attackers could plant hidden prompt injection payloads inside public-facing Web-to-Lead forms, a standard Salesforce feature that allows external users to submit data that flows directly into CRM records.

Once triggered, the injected payload could instruct the agent to quietly query and exfiltrate sensitive account data, including company names, deal sizes and other CRM fields, using DNS-based exfiltration techniques that evaded Salesforce's Trusted URLs redaction controls, a safeguard designed to prevent exactly this kind of data leakage through outbound links.

Zenity reported the vulnerabilities to Salesforce in June, and Salesforce fully fixed the URL redaction bypass, which remediated the issues, on August 18.

In a typical General CRM deployment, that includes accounts, contacts, and more,” the Zenity report noted.

Critically, the attacker could perform a successful compromise without direct access to the target organization and the attack required no click or credential theft.

Any AI agent that reads or processes records submitted by external, untrusted sources, renders links, images, or other rich content back to users, and holds tool access to sensitive backend data “has the same three ingredients sitting in the same place,” creating a latent path for prompt injection-driven exfiltration.

While the specific vulnerabilities in SalesBleed have been fixed, the Zenity researchers emphasized that the underlying risk pattern is not unique to Agentforce.

The lead submission alone was enough to seed the payload, and normal agent operation did the rest.

When an Agentforce agent later processed that record as part of normal business operations, the embedded instructions would hijack the agent's behavior.

What happened

The findings, published September 24by Zenity’s threat research team, detail an attack chain dubbed ‘SalesBleed.’ According to the report , attackers could plant hidden prompt injection payloads inside public-facing Web-to-Lead forms, a standard Salesforce feature that allows external users to submit data that flows directly into CRM records.

Once triggered, the injected payload could instruct the agent to quietly query and exfiltrate sensitive account data, including company names, deal sizes and other CRM fields, using DNS-based exfiltration techniques that evaded Salesforce's Trusted URLs redaction controls, a safeguard designed to prevent exactly this kind of data leakage through outbound links.

What changed

Zenity reported the vulnerabilities to Salesforce in June, and Salesforce fully fixed the URL redaction bypass, which remediated the issues, on August 18.

In a typical General CRM deployment, that includes accounts, contacts, and more,” the Zenity report noted.

Who is affected

Critically, the attacker could perform a successful compromise without direct access to the target organization and the attack required no click or credential theft.

Any AI agent that reads or processes records submitted by external, untrusted sources, renders links, images, or other rich content back to users, and holds tool access to sensitive backend data “has the same three ingredients sitting in the same place,” creating a latent path for prompt injection-driven exfiltration.

Why it matters

While the specific vulnerabilities in SalesBleed have been fixed, the Zenity researchers emphasized that the underlying risk pattern is not unique to Agentforce.

Technical details

The lead submission alone was enough to seed the payload, and normal agent operation did the rest.

Attribution

Infosecurity Magazine: The findings, published September 24by Zenity’s threat research team, detail an attack chain dubbed ‘SalesBleed.’ According to the report , attackers could plant hidden prompt injection payloads inside public-facing Web-to-Lead forms, a standard Salesforce feature that allows external users to submit data that flows directly into CRM records.

What to watch next

Watch for updated vendor guidance and fixed-version details.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am