Salesforce Agentforce AI Agent Vulnerability

A Salesforce Agentforce AI agent vulnerability, publicly disclosed September 24 by research firm Zenity Labs under the name “SalesBleed,” let an attacker plant a hidden instruction in an ordinary sales lead form and later exfiltrate CRM data with zero clicks, once an employee simply asked their AI agent to look at the newest lead. Salesforce fixed all three underlying flaws by August 19, before today’s public write-up, but the attack chain it exposes is not unique to Salesforce.
What Happened
The attack starts with something completely mundane: an attacker submits a lead through an organization’s public Web-to-Lead form, Salesforce’s standard lead-capture mechanism, with a hidden prompt injection buried in one of the text fields. The malicious instructions sit dormant in the CRM until an employee later asks their Agentforce agent something entirely ordinary, such as “check my latest leads and help me with the newest one.” The agent reads the poisoned lead, inherits the hidden instructions, queries the Accounts table for sensitive fields such as company name and deal size, and exfiltrates the values by encoding them into a subdomain string sent to an attacker-controlled hostname, all without the employee clicking anything or realizing an instruction beyond their own request was ever executed.
A third flaw let an attacker weaponize the agent itself to send phishing messages under its trusted identity. The root cause was a set of edge cases in Agentforce’s “Trusted URLs” allowlist and redaction control, meant to block agents from fetching unapproved external URLs. Zenity found inconsistent domain recognition and character-handling gaps between the redactor and downstream rendering, letting a malformed URL slip through while still being treated as fetchable inside an HTML image source. Salesforce fixed all three issues within roughly two weeks of Zenity’s report, completing remediation by August 19, five weeks before today’s public disclosure. No CVE was assigned, this was a SaaS-side fix and no customer-side patching action is required.
Why It Matters
No patching action is required here, which is exactly what makes this a governance story rather than a patch-Tuesday story. This is the fourth documented 2026 case of an AI agent hijacked via untrusted input it was never designed to treat as instructions, after Agentjacking via Sentry bug reports in June, MCPwn, and the TrapDoor supply-chain campaign hiding instructions in configuration files. The pattern repeats across unrelated products and vendors: any system where an AI agent processes attacker-reachable input, a support ticket, a lead form, a document, and can also take real actions such as querying a database, is a candidate for the same class of attack, regardless of how well any one vendor patches this specific instance.
Salesforce is heavily deployed across DACH sales and CRM operations, and Agentforce adoption is accelerating exactly as many organizations evaluate agentic AI more broadly. That timing makes this a useful prompt to ask not “did we patch this” but “which AI agents in our organization can read something an outsider submitted, and what can those agents actually do next.”
What You Should Do Now
- Inventory which AI agents in your organization process externally-submitted content, web forms, support tickets, uploaded documents, incoming emails, and list what each agent is permitted to do once it reads that content.
- Verify: for any Salesforce Agentforce deployment, confirm the Trusted URLs allowlist and redaction control is enabled and running a current, patched version, since this specific bypass is now fixed.
- Review CRM and AI agent action logs for anomalous outbound requests, unusual subdomain patterns, or data queries that do not match the employee’s stated task. Make this a standing habit: this incident will be old news long before the underlying risk class disappears.
- Treat every AI agent deployment as a governance question about data flow first and an IT configuration question second, since the underlying risk class will resurface in other products this Salesforce fix does not touch.
DIESEC Perspective
We keep seeing the same structural flaw wearing a different vendor’s clothes: an AI agent that cannot reliably distinguish data to read from instructions to follow. Four unrelated products, four unrelated vendors, one identical root cause. No single patch resolves the class of risk, and DACH boards evaluating agentic AI deployments should ask which of their own AI agents could be handed the same kind of poisoned input tomorrow.
Not sure which AI agents in your organization can be reached by outside input, and what they’re allowed to do once they read it? Contact DIESEC for a rapid AI agent exposure and configuration review.
Sources: Zenity Labs | SecurityWeek
Published: 2026-09-30 | Category: AI Security | ~4 min read

