Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
9 Articles
9 Articles
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
'SalesBleed' security flaws 'lead to very unexpected consequences'
Salesforce Agentforce Got Zero-Clicked Through Its Own Web Form – and the Attack Vector Is in Every Agent That Combines These Three Things
Enterprise web forms designed to ingest data from unknown parties are now active breach vectors. The disclosure of SalesBleed, a series of vulnerabilities in Salesforce Agentforce, confirms that a single poisoned record can trigger zero-click data exfiltration – no privilege escalation, no user click, no attachment. The entry point is the most basic form on […]
Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
Given that contaminated lead records persist, a single malicious submission could be triggered repeatedly whenever staff reviews that lead. Salesforce stated it has strengthened the affected mechanisms, and separate reports indicate no evidence of exploitation in the wild. The company also updated default settings for certain Agentforce actions in Slack to require user confirmation before
Zenity Labs Uncovers SalesBleed, 3 Salesforce Agentforce Flaws Enabling Zero-Click CRM Data Theft and AI Agent Impersonation
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










