Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› SalesBleed Salesforce Agentforce 2026: How Poisoned Web-to-Lead Records…
Breach analysis Incident: 24 Sep 2026

SalesBleed Salesforce Agentforce 2026: How Poisoned Web-to-Lead Records Turned AI Agents Into Zero-Click Data Thieves and Phishers

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 9 min read
On this page

On 24 September 2026, Zenity Labs disclosed SalesBleed: three now-fixed vulnerabilities in Salesforce Agentforce. They let an outside attacker plant instructions in a public Web-to-Lead form and have Salesforce's own AI agents steal CRM data and send phishing messages in Slack. Nobody had to click anything, and the attacker never logged in to the victim's Salesforce tenant. When an employee later asked an agent about new leads, the agent read the poisoned lead, queried account records and leaked the results through image links and Slack link previews. This got past Salesforce's Trusted URLs controls, the very safeguard added after the similar ForcedLeak flaw in 2025. A third flaw let the agent post Slack messages under its own trusted identity with no user approval. Salesforce fixed all three before disclosure, and no exploitation has been reported.

Key takeaways

  • Zenity reported three Agentforce vulnerabilities to Salesforce on 1 June 2026. Salesforce confirmed it was working on fixes the next day. Zenity confirmed all three fixes on 21 September and disclosed on 24 September.
  • The entry point was the same as ForcedLeak's: indirect prompt injection in a public Web-to-Lead form, triggered when an employee asks an Agentforce agent about leads.
  • Data left through URLs that Salesforce's Trusted URLs redaction failed to block. It did not recognise hostnames with unknown top-level domains, and certain characters broke its URL parsing. Slack link unfurling gave a second zero-click exfiltration path.
  • The Slack "Reply to a Slack Thread" action needed no user confirmation and showed no attribution to the invoking user. An insider or an injected prompt could therefore send phishing messages under the agent's trusted identity.
  • SalesBleed was responsibly disclosed research, and the specific chains no longer work. Zenity warns that any agent that reads external records, renders links or images, and holds data access has "the same three ingredients sitting in the same place".

At a glance

OrganisationSalesforce (Agentforce, including its Slack integration); Agentforce customers using Web-to-Lead
WhenReported 1 June 2026; fixes confirmed by Salesforce 18 August 2026; all three fixes confirmed by Zenity 21 September 2026; disclosed 24 September 2026
AttackerNone known. Found and reported by Zenity Labs, the research team at Zenity
Entry pointA public Web-to-Lead form submission carrying hidden instructions, later processed by an Agentforce agent
Identities abusedThe Agentforce agent acting with its query access to CRM records on behalf of an employee; the agent's trusted Slack identity, used to post messages without user approval or attribution
ImpactPotential zero-click exfiltration of CRM data such as accounts and deal sizes, and phishing under the agent's identity; no confirmed real-world victims
CategoryAgentic AI and AI agents, NHI. Incident class: agent vulnerability (vulnerability, no confirmed breach)

What happened

Salesforce's Web-to-Lead feature lets anyone on the internet submit a form that becomes a lead record in the CRM. Agentforce agents can read those records and query others. In 2025, Noma Security's ForcedLeak showed that hidden instructions in a lead could make Agentforce send data to an expired, still-trusted domain. Salesforce responded by enforcing Trusted URLs, which restrict the external destinations Agentforce can reach and redact links and images pointing elsewhere.

Zenity found that Trusted URLs could be bypassed. According to The Register, it "didn't register hostnames ending in an unrecognized top-level domain", and adding certain characters interfered with how URLs were parsed. Zenity's injected lead told the agent to query the Accounts table, take fields such as company name and deal size, put them into a subdomain of an attacker-controlled host, and print it back as an HTML image tag. The front end fetched the image automatically, and the DNS lookup carried the data out. Zenity demonstrated the attack when an employee asked the agent to "check my latest leads and help me with the newest one." A second path used Slack. When employees worked with the agent through Slack, specially built links triggered Slack's link unfurling, which sent the CRM data to the attacker as soon as the link appeared.

The third flaw was in the "Reply to a Slack Thread" action of Agentforce's default Slack Knowledge subagent template. Zenity says it did not ask the user for confirmation before sending a message and did not show which user had invoked it. Combined with the URL bypass, a malicious insider, or an external attacker through the same poisoned lead, could have the agent post phishing links under its own trusted identity while staying anonymous.

Zenity reported all three issues on 1 June 2026, and Salesforce confirmed it was working on fixes the next day. Zenity's disclosure timeline says Salesforce confirmed its fixes on 18 August and Zenity confirmed the Trusted URLs fix on 19 August. The Register reports Zenity confirmed all three fixes on 21 September. Zenity co-founder and CTO Michael Bargury told The Register: "The bigger lesson here is about what it takes to keep AI agents contained."

Timeline

DateEvent
25 September 2025ForcedLeak, an earlier Web-to-Lead prompt injection in Agentforce, is disclosed; Salesforce enforces Trusted URLs.
1 June 2026Zenity reports the three SalesBleed vulnerabilities to Salesforce.
2 June 2026Salesforce confirms it is working on fixes.
18 August 2026Salesforce confirms its fixes.
19 August 2026Zenity confirms the fix for the Trusted URLs bypass.
21 September 2026Zenity confirms all three vulnerabilities are fixed.
24 September 2026Zenity publishes SalesBleed.

How it happened: the identity attack path

  1. Untrusted input in a trusted system. Anyone could write a lead record through the public Web-to-Lead form, and the agent later read it as normal business data.
  2. The agent's access did the work. The agent held query access to CRM records on behalf of the employee, so the injected instructions could reach accounts, contacts and deal data without any attacker login.
  3. An allowlist with gaps. Trusted URLs failed on unknown top-level domains and on specially crafted URLs, so the agent's output could still point at attacker infrastructure.
  4. Zero-click outbound channels. Automatic image fetching and Slack link unfurling carried the data out the moment the agent's reply was displayed.
  5. An agent identity without accountability. The Slack reply action posted as the agent, with no user confirmation and no visible link to the person who triggered it, which made the agent an anonymous phishing channel.

Impact

  • Potential: zero-click theft of any CRM data the agent's query tool could reach. Zenity notes that in a typical deployment this includes accounts and contacts.
  • Phishing: messages sent in Slack under a trusted agent identity, without attribution to the person or payload behind them.
  • Confirmed: no in-the-wild exploitation reported. All three issues were fixed before disclosure.

What this means for NHI and AI agent security

SalesBleed is the second time in a year that a public lead form has turned Agentforce agents against their own organisations. That repetition is the point. The underlying pattern is an agent that reads untrusted input, holds access to sensitive data, and can send output somewhere. Fixing one bypass does not remove it. Zenity's phrase, "the same three ingredients sitting in the same place", describes most enterprise agents today.

The phishing flaw is the more distinctly identity-related finding. The Slack action let the agent speak with its own trusted identity, with nothing tying the message to the human or input behind it. Agent identities need the same accountability as human ones: actions should be attributable to an invoking principal, and high-risk actions such as sending messages need confirmation. The OWASP Top 10 for Agentic Applications covers these risks under agent goal hijack, tool misuse and human-agent trust exploitation.

Recommendations

  • Scope agent data access to the task. An agent helping with leads does not need to query every account and deal. Limit its tools and fields. See our AI Agent Authorisation Guide.
  • Treat externally submitted records as untrusted. Web forms, emails and tickets from outside should not reach agents as trusted context without filtering or isolation.
  • Close outbound channels agents do not need. Block agents from rendering external images and links where possible, and review allowlists for parsing gaps and expired domains.
  • Require confirmation and attribution for agent actions. Messages, emails and record changes sent by agents should need user approval and show who triggered them. See our Enterprise AI Copilot Security Guide.
  • Govern SaaS agents like connected apps. Inventory agents and their integrations in Salesforce and Slack, and review their permissions as you would OAuth apps. See our SaaS and OAuth App Governance Guide.

Frequently asked questions

What is SalesBleed?

SalesBleed is Zenity Labs' name for three vulnerabilities in Salesforce Agentforce. They let hidden instructions in a public Web-to-Lead submission make Agentforce agents leak CRM data without any clicks, and send phishing messages in Slack under the agent's identity.

Was SalesBleed exploited?

No exploitation has been reported. Zenity reported the issues on 1 June 2026, Salesforce fixed them, and Zenity confirmed all fixes on 21 September before publishing on 24 September.

How is SalesBleed different from ForcedLeak?

Both start with a prompt injection in a Web-to-Lead form. ForcedLeak sent data to an expired domain on Salesforce's allowlist. SalesBleed bypassed the Trusted URLs controls added after ForcedLeak, used Slack link previews as a second channel, and added a phishing path through the agent's Slack identity.

ForcedLeak Salesforce Agentforce 2025 · ShinyHunters Salesforce data theft campaign 2025 · EchoLeak 2025 · Agentic AI Security Guide · Permission-Aware RAG Guide

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as agents act inside CRMs and chat tools with access to sensitive data and trusted identities. Our NHI Foundation Level Training Course gives teams the practical grounding to scope and govern that access.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org