Security researchers at Zenity Labs have disclosed a set of zero-click vulnerabilities in Salesforce Agentforce, dubbed SalesBleed, which allow attackers to exfiltrate sensitive CRM data using nothing more than a standard web form submission. Published on 24 September 2026, the findings highlight a critical flaw in how AI agents process untrusted external inputs, enabling silent data breaches without requiring any interaction from internal staff.

The Attack Chain: No Clicks, Just Code

The SalesBleed exploit leverages Salesforce’s Web-to-Lead feature, a common tool for capturing customer inquiries. Attackers embed hidden prompt injection payloads directly into the form submission. When the Agentforce AI agent processes this record during its normal operational cycle, the embedded instructions hijack the agent's behavior. Instead of simply logging the lead, the agent is tricked into querying sensitive account data, such as company names and deal sizes. Once the data is retrieved, the agent exfiltrates it using DNS-based techniques that successfully bypassed Salesforce’s Trusted URLs redaction controls. This method allowed the attacker to extract information without authenticating into the target’s Salesforce environment. The entire attack vector required no phishing email, no malicious attachment, and no user click from anyone inside the business organization.

The Three Ingredients of Risk

Zenity Labs emphasizes that while Salesforce fixed the specific URL redaction bypass on 18 August 2026, the underlying risk pattern is not unique to Agentforce. The researchers identified three structural ingredients that create a latent path for prompt injection-driven exfiltration in any AI agent system. First, the agent must read or process records submitted by external, untrusted sources. Second, the agent must be capable of rendering links, images, or rich content back to a user interface. The third ingredient is the agent’s access to sensitive backend data via tool capabilities. If an AI agent combines these three traits—external input ingestion, rich content rendering, and backend data access—it becomes a viable target for similar attacks. The SalesBleed report notes that while the test payload targeted company names and deal sizes, the injection could theoretically access any data reachable by the agent’s query tools, including full account and contact details.

Brokerage Compliance and Liability

For industries like financial brokerage, this vulnerability transcends simple technical debt and becomes a compliance nightmare. Australian brokers, for instance, operate under strict data controller obligations. If an AI agent deployed in a brokerage exfiltrates client CRM data via a mechanism like SalesBleed, liability does not automatically shift to the vendor. The brokerage remains the data controller for client information, meaning the legal and financial fallout rests with the business, not the software provider. Zenity’s analysis urges organizations to ask their AI vendors three critical questions: Does the agent treat externally submitted text as instructions or just data? Can the agent render outbound links or images based on record content? And what is the scope of data the agent can query? If a vendor cannot provide clear, documented answers to these questions, the organization is operating with an unmitigated risk profile on live client data.

Key Takeaways

  • Salesforce fixed the specific SalesBleed URL redaction bypass on 18 August 2026, but the architectural risk remains prevalent across AI agent platforms.
  • The attack required zero user interaction, relying entirely on the AI agent’s autonomous processing of poisoned web form inputs.
  • Data exfiltration was achieved via DNS-based techniques that evaded standard Trusted URLs redaction controls.
  • Liability for data breaches caused by AI agents often remains with the deploying organization, not the vendor, due to data controller obligations.
  • Organizations must audit their AI agents for the 'three ingredients' of risk: external input processing, rich content rendering, and backend data access.

The Bottom Line

SalesBleed proves that AI agents are now high-value targets for zero-click exploits. Organizations must treat external inputs as hostile code and enforce strict data controller liability regardless of vendor assurances.