Threat

Salesforce Agentforce Zero-Click Data Exfiltration Risks

Page published

Earliest dated coverage: 26 Sep 2026 · First observed: 10 Oct 2026 · Latest dated coverage: 26 Sep 2026

Coverage timeline

26 Sep 2026aisecmaster.com

Single-source incident — one report is available.

Why it matters

SalesBleed shows that an autonomous AI agent with legitimate access to business records can be weaponized through ordinary-looking customer-submitted content, turning indirect prompt injection into silent, zero-click exfiltration of sensitive CRM data.

Zenity Labs disclosed SalesBleed, a zero-click attack chain against Salesforce Agentforce in which hidden indirect prompt-injection payloads submitted via Web to Lead are later processed by an Agentforce agent, then combined with weaknesses in Salesforce Trusted URL handling to exfiltrate CRM data to an attacker-controlled destination without any victim click or authentication.