TL;DR
- Security researchers at Zenity Labs disclosed zero-click vulnerabilities in Salesforce Agentforce, published 24 September 2026, under the name SalesBleed.
- An attacker could plant hidden instructions inside a public Web-to-Lead form. No login, no click from anyone inside the business was required.
- The AI agent processed the poisoned record during normal operations and quietly sent CRM data out using DNS-based exfiltration.
- Salesforce fixed the specific URL redaction bypass on 18 August 2026. Zenity says the underlying pattern is not unique to Agentforce.
- Any AI agent that reads externally submitted records, renders links or images, and holds backend data access carries the same three risk ingredients.
The attack had no drama. No phishing email. No malicious attachment. Just a form submission.
What did the SalesBleed attack actually do?
Zenity Labs disclosed a set of zero-click vulnerabilities in Salesforce Agentforce. The attack chain named SalesBleed worked like this: an attacker submitted a Web-to-Lead form, a standard Salesforce feature that lets external users send data directly into CRM records. Inside that submission, the attacker embedded hidden prompt injection payloads. When the Agentforce AI agent later processed that record during normal business operations, the embedded instructions hijacked the agent's behaviour.
The agent then quietly queried and exfiltrated sensitive account data, including company names and deal sizes, using DNS-based exfiltration techniques that evaded Salesforce's Trusted URLs redaction controls. The attacker never authenticated into the target's Salesforce environment. No one inside the business clicked anything.
Zenity reported the vulnerabilities to Salesforce in June 2026. Salesforce fully fixed the URL redaction bypass on 18 August 2026.
Why does this matter if your brokerage does not use Salesforce?
Zenity's researchers were direct on this point. The specific vulnerabilities have been fixed. The underlying risk pattern has not, because it is not unique to Agentforce.
They identified three ingredients that, when combined, create a latent path for prompt injection-driven exfiltration:
- The AI agent reads or processes records submitted by external, untrusted sources.
- The AI agent renders links, images, or other rich content back to a user interface.
- The AI agent holds tool access to sensitive backend data.
Zenity's report noted that their test payload asked for company names and deal sizes, but the injection could have asked for anything the agent's query tool could reach, including accounts, contacts, and more.
If your brokerage runs an AI agent that reads what comes in through an enquiry form or any other public-facing input, that is the first ingredient. The question is whether your deployment also has the second and third.
This is the same structural concern raised in the ASD warning about AI agents taking unexpected actions, and it connects to the access-control questions covered in the OpenAI Medicare breach analysis. Researchers keep finding this pattern in production systems.
What should a broker actually check?
Three questions worth putting to your AI vendor or internal build team.
Does the agent read externally submitted text as instructions? A well-configured AI agent should treat anything a stranger types as data to be stored or routed, not as a command to be executed. If your agent reads a lead's free-text message and acts on its content directly, the first ingredient is present.
Does the agent render links or images back to a user interface? If the agent can construct and display a URL or image based on content it read from a record, an attacker can use that to exfiltrate data to an external server.
What data can the agent query? An agent with read access to your full client database or deal pipeline is a much larger target than one scoped to a narrow task. Principle of least privilege applies here exactly as it does to human staff accounts.
If your vendor cannot answer these questions clearly, that is itself useful information. For brokers thinking about how to structure agent permissions before deployment, agent validation and stopping before irreversible actions covers the design logic in more detail.
The compliance angle brokers should not ignore?
Australian brokers operate under obligations around client data that make this more than a technology problem. If an AI agent deployed in your brokerage were to exfiltrate client CRM data through a mechanism like SalesBleed, the question of who is responsible does not resolve to the vendor. Data controller obligations sit with the brokerage.
Ask your vendor whether they have documented their approach to prompt injection risk. That documentation should exist. If it does not, ask for it in writing.
The full Zenity Labs disclosure is available via the Infosecurity Magazine report and is worth reading if you are evaluating or already running an AI agent on client-facing data.
FAQs
What is prompt injection and why does it affect AI agents reading enquiry forms?
Prompt injection is when an attacker embeds hidden instructions inside content that an AI agent will read and act on. If your AI agent reads free-text submitted through a public form and treats that text as something to act on rather than just store, an attacker can redirect the agent's behaviour. The SalesBleed research showed this working against a production Salesforce deployment.
Has Salesforce fixed the SalesBleed vulnerability?
Salesforce fixed the specific URL redaction bypass on 18 August 2026, which remediated the issues described in the SalesBleed disclosure. Zenity's researchers noted that the underlying three-ingredient risk pattern is not unique to Salesforce Agentforce and can exist in any AI agent with the same combination of external input, rich content rendering, and backend data access.
Does this risk apply to voice agents as well as text-based AI agents?
The SalesBleed research focused on a text-based CRM agent reading form submissions. A voice agent that transcribes caller input and passes that transcription to an AI agent for action could carry a similar risk if the model treats caller-supplied text as instructions and holds access to sensitive data. The same three-ingredient check applies.
What is the minimum a broker should do after reading about SalesBleed?
Ask your AI vendor three questions: does the agent treat externally submitted text as instructions, can it render outbound links or images based on record content, and what data can it query. Document the answers. If all three ingredients are present, ask what controls exist to prevent prompt injection-driven exfiltration before continuing to use it on live client data.
Who is liable if an AI agent in my brokerage exfiltrates client data?
This depends on your specific contracts and applicable Australian privacy and credit legislation. As a general principle, the brokerage is the data controller for client information it holds, and vendor liability clauses vary widely. Treat this as your risk to manage, not your vendor's, and apply the same due diligence you would to any system holding client financial data.
Originally published at theautomate.io.
Top comments (0)