Salesforce Patched SalesBleed AI Platform Vulnerabilities
Three flaws in the Agentforce platform allowed for unauthorized data access and identity-based phishing via AI agents.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust AI agents to handle sensitive business data securely?
Salesforce has patched three vulnerabilities collectively known as SalesBleed that permitted zero-click data exfiltration and impersonation through its Agentforce platform. The security issues, which have now been fully remediated, allowed attackers to weaponize AI agents for unauthorized CRM data access and phishing.
Why it matters
These vulnerabilities, which stemmed from insecure URL controls and integration gaps, highlight the risks of indirect prompt injection in enterprise AI agents. They demonstrate how external inputs can be used to hijack automated workflows, specifically through platforms like Slack.
The SalesBleed chain consisted of three distinct vulnerabilities that enabled zero-click exfiltration and identity-based phishing. Salesforce confirmed all three vulnerabilities were successfully remediated by September 21, 2026.
The players
Salesforce
A cloud-based software company providing a customer relationship management platform and AI-driven automation services.
Zenity Labs
A security research firm focused on identifying vulnerabilities within enterprise AI agents and large language model integrations.
Slack
A communication platform owned by Salesforce that integrates AI agents into enterprise workflows.
The details
The exploit chain relied on indirect prompt injection, where malicious instructions are embedded into public Web-to-Lead forms. When an employee queries an AI agent, it inadvertently executes these instructions, leading the agent to embed sensitive CRM data within image requests sent to attacker-controlled servers. Additionally, the flaws leveraged Slack's URL unfurling feature to facilitate external requests and permitted the 'Reply to a Slack Thread' action to trigger messages without user approval.
Timeline
June 1, 2026: Zenity Labs reported the vulnerabilities to Salesforce.
June 2, 2026: Salesforce confirmed it was working on fixes.
August 19, 2026: Zenity confirmed the fix for the URL redaction bypass.
September 21, 2026: Zenity confirmed all three vulnerabilities were fixed.
September 24, 2026: The Register published the report on the vulnerabilities.
The Tech Race
This incident serves as a real-world validation of the threat posed by indirect prompt injection, a category prioritized in the OWASP Top 10 for Large Language Model Applications. The remediation underscores the competitive necessity for AI-integrated platforms to secure internal agent pathways against external data manipulation.
Users of Salesforce Agentforce and Slack integrations do not need to take manual action, as all three vulnerabilities were patched by September 21, 2026. Developers should ensure their internal URL redaction policies and agent approval workflows remain up to date to prevent similar exploits.
The takeaway
Enterprises must recognize that AI agents can turn public-facing inputs into vectors for internal data breaches. Security teams should monitor for future disclosures regarding indirect prompt injection and maintain strict validation for all external URL requests within their AI tech stack.
Further reading
For more information on securing enterprise AI integrations, browse our Cybersecurity section.
Live Poll
Do you trust AI agents to handle sensitive business data securely?









