www.darkreading.com 24 Sept 2026, 21:04 UTC

Salesforce Agentforce Flaws Let Attackers Hijack AI Agents via Forms

Salesforce Agentforce Flaws Let Attackers Hijack AI Agents via Forms
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS at Zenity have identified three weaknesses in Salesforce Agentforce, collectively dubbed “Salesbleed”, that could let attackers inject instructions through public Web-to-lead forms. Those prompts could cause an AI agent to access or exfiltrate internal Salesforce data using the permissions already granted to it. The weaknesses could also be chained with Agentforce’s Slack integration: an attacker might instruct an agent to post a phishing message in an internal Slack thread.

Because the message could appear without clear attribution, it might seem to come from a legitimate employee or help desk. The researchers said data theft through a single request was limited by the amount that could fit in a subdomain, although repeated automated requests could increase the impact.

Salesforce told Dark Reading that the weaknesses have no CVE numbers and that it has found no evidence of exploitation by real attackers. The company said it changed default settings for certain Agentforce actions in Slack so that users must confirm messages before they are sent, and is contacting customers to review their configurations. Salesforce also replaced its earlier regex-based URL filtering, which researchers bypassed using alternative URL formats, with specification-compliant URL parsing.

It is additionally routing URL inspection through a single gateway to apply more consistent controls. Zenity warned that the broader risk comes from combining agents’ access to sensitive data and external input channels, while limited visibility into agent actions can make misuse difficult to detect.

View full article

Article by CyberSIXT