{
  "id": 9947524,
  "title": "Salesforce patches Agentforce flaws enabling zero-click data theft",
  "url": "https://urgent.news/2026/09/26/salesforce-patches-agentforce-flaws-enabling-zero-click-data-theft",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-26T08:57:28.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/salesforce-patches-agentforce-flaws-enabling-zero-click-data-theft/"
  },
  "original_language": "en",
  "account": "Salesforce has addressed three security flaws in its Agentforce AI platform, which researchers discovered could permit unauthorized data extraction from customer relationship management systems without requiring users to click on malicious links. These vulnerabilities, dubbed SalesBleed by cybersecurity firm Zenity Labs, were made public on September 24 following patches and testing. Salesforce confirmed it had not detected any exploitation of these flaws. The attack process starts with the Web-to-Lead feature in Salesforce, allowing external parties to submit data directly into CRM records. Attackers could insert hidden instructions within a lead submission, which would remain in the database until an Agentforce agent reviewed the leads. This action could cause the agent to interpret the embedded text as commands, leading it to retrieve sensitive data from the Accounts table. The attackers then exploited weaknesses in Agentforce's Trusted URLs protection, a feature meant to block unauthorized URLs. By manipulating unrecognised top-level domains and characters, researchers created a pathway for data exfiltration, allowing stolen CRM data to be inserted into a subdomain controlled by the attacker and retrieved via an HTML image tag. Additionally, if Agentforce was integrated with Slack, the compromise could allow attackers to send phishing messages directly from Slack threads. Furthermore, another flaw enabled compromised agents to be used as phishing channels within Slack. The company has since updated its Trusted URLs mechanism and Slack defaults to require confirmation for certain actions, identifying the user who triggered the action. Zenity Labs reported these vulnerabilities to Salesforce on June 1, and the company acknowledged them the following day. The fixes for the URL bypass were implemented on August 19, and all patches were confirmed by September 21. This incident highlights the risks associated with integrating AI agents that have access to privileged data and the potential for malicious actors to exploit seemingly innocuous data entries to gain deeper access to corporate systems.",
  "summary": "Salesforce has patched three vulnerabilities in its Agentforce artificial intelligence platform that researchers said could have enabled unauthenticated attackers to extract sensitive customer relationship management data without victims clicking malicious links. The weaknesses, collectively named SalesBleed by Zenity Labs, were publicly disclosed on September 24 after fixes were completed and…",
  "key_points": [
    "Salesforce patches three Agentforce security flaws enabling zero-click data theft.",
    "Researchers discovered vulnerabilities dubbed SalesBleed by Zenity Labs.",
    "Fixes implemented on August 19, preventing exploitation of AI-powered CRM platform."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}