cloud-identity • SecurityWeek

SalesBleed in Salesforce Agentforce ermöglichte Zero-Click-Exfiltration von CRM-Daten

Zenity Labs enthüllt drei SalesBleed-Schwachstellen in Salesforce Agentforce.

SalesBleed in Salesforce Agentforce ermöglichte Zero-Click-Exfiltration von CRM-Daten

Three vulnerabilities in Salesforce Agentforce — the AI agent platform tied to the company's CRM — could let attackers hijack trusted agents, steal sensitive customer data and spread phishing internally. Zenity Labs, which reported the issues on June 1, 2026, calls the chain SalesBleed. The entry point is Salesforce's own Web-to-Lead form: an official lead-collection path that also feeds straight into the CRM. Malicious instructions injected into a lead stayed dormant until an employee asked an Agentforce agent to process the submission — at which point the agent executed the hidden commands.

Two flaws enabled zero-click exfiltration. Trusted URLs, the control meant to stop Agentforce from fetching URLs and images from untrusted sources, failed to recognise top-level domains and could be tampered with through character sequences in URL parsing. HTML image tags shipped data from leads and accounts tables to an attacker server. Agentforce could simultaneously report that content had been blocked by security policy — even though CRM data had already left the organisation. That makes traditional user warnings misleading: the UI says no while exfiltration already succeeded.

The third bug hits the Agentforce–Slack integration. The same poisoned Web-to-Lead could make the agent post to internal Slack channels under the agent's trusted identity. Specially crafted links caused Slack preview requests to carry CRM data to attacker infrastructure as soon as links appeared. Employees therefore saw a message from a system they already trust — not from an unknown sender. Anyone who clicked and surrendered credentials could open email, Slack, source repos and other apps behind the compromised identity.

Salesforce confirmed all three bugs were fixed by August 19, 2026. For Nordic organisations running Agentforce the lesson is broader than a one-off patch: AI agents that read customer data and hold write rights in collaboration tools create a new attack surface where social engineering and misconfiguration merge. Review which channels agents may post to, which URL policies apply, and whether Web-to-Lead input is sanitised before agents process it. Zero-click means no employee needs to click a malicious link for data to leak — only that someone asks the agent to "look at this lead".

Concrete steps for CRM and security leaders

1. Verify Salesforce Agentforce patches through 19 August 2026 are applied in every org. 2. Minimise Agentforce privileges for CRM tables and Slack channels. 3. Audit Trusted URL lists; test that unknown TLDs and image URLs are truly blocked. 4. Sanitize and monitor Web-to-Lead content before AI agents may process it. 5. Train staff: treat unexpected agent messages in Slack as unverified until confirmed out-of-band.

Evidence Rail

  • Confirmed: Zenity Labs technical report; Salesforce remediation of all three bugs by 19 August 2026.
  • Reported: SecurityWeek summary of the zero-click and Slack chains.
  • Unconfirmed: Whether SalesBleed was exploited against named customers before patching.

In Brief

  • SalesBleed let attackers steer Agentforce via Web-to-Lead into CRM exfiltration without clicks.
  • Trusted URLs could be bypassed so data leaked while the UI reported "blocked".
  • Slack integration could turn the AI agent into an internal phishing sender — patch and minimise privileges.

Quellen & Referenzen

← Alle Nachrichten Werkzeuge