Monday, 28 September 2026

Where technology leaders come to think out loud

The BriefCybersecurity

Agentforce flaws let a poisoned web lead leak CRM data over DNS

Salesforce fixed the Trusted URLs bypasses in August and has changed its Slack defaults, but the attack needed no login, no click and only the permissions the stock CRM subagent ships with

The facts
  • Zenity Labs reported the flaws to Salesforce on 1 June 2026 and published on 24 September.
  • Salesforce confirmed its fixes on 18 August; Zenity verified the patch on 19 August.
  • Two of the three flaws were zero-click; the third turned a Slack-connected agent into a phishing sender.
  • Salesforce’s statement, published by SecurityWeek on 25 September, says some Agentforce Slack actions now require user confirmation by default.
What it means for partners

Every UK Salesforce partner has customers with Web-to-Lead forms, and some will have Agentforce trials running on the stock CRM subagent. That combination is the exposure, and Salesforce’s fix closes this chain rather than the class: any public intake form an agent later reads carries the same shape of risk.

That points to a scoped, billable review of which subagents hold Query Records across objects, how Trusted URLs is configured and whether Slack actions require confirmation. MSSPs that can scope and monitor agents win the retainer; consultancies that build Agentforce topics without a security review will be explaining the leak.

“We need to think beyond whether an agent has guardrails and ask what happens when those guardrails are bypassed.”Michael Bargury, co-founder and CTO, Zenity

Zenity Labs on 24 September published details of three flaws in Salesforce Agentforce, which it calls SalesBleed, that let an attacker pull restricted customer relationship management (CRM) records out of a customer’s instance by submitting one Web-to-Lead form.

Web-to-Lead endpoints are public by design. The attacker files a lead that carries instructions in one field. Nothing happens until a sales user asks the agent to review the latest leads. The agent reads the poisoned record, follows its instructions, pulls company names and deal sizes from the Accounts table through its Query Records tool and writes them into the subdomain of a URL. Rendered as an image tag or unfurled by Slack, that URL triggers a Domain Name System (DNS) lookup the attacker’s nameserver records. Salesforce’s Trusted URLs control should have redacted the link, but it did not recognize the .fun top-level domain and disagreed with browsers about where a URL ends, so curly braces and square brackets carried it through.

A default agent with too much reach

The injection could reach account data because the stock General CRM subagent ships with read access to both leads and accounts. The third flaw let the agent’s Slack integration post phishing messages under the agent’s own trusted identity.

Zenity reported the findings on 1 June and Salesforce confirmed its fixes on 18 August. A Salesforce spokesperson told SecurityWeek the company had “no evidence at this time that the reported issue was exploited against any customer” and that certain Agentforce actions in Slack now require user confirmation by default. Zenity, which sells agent security software, argues the same mix of untrusted input, broad permissions and rendered links exists beyond Salesforce, as Digit reported on 28 September.

AdvertisementZoomInfo
More from The BriefAll briefs
Bytes Technology Group

Bytes lifts its FY27 outlook as costs hold back operating profit

Arctic Wolf

Arctic Wolf opens a sensorless MDR tier to MSPs only

Vectra AI

Vectra AI launches Ascent partner program with three levels

Capgemini

Capgemini sees $230bn of bank payments revenue at risk from stablecoins

Get the briefs every week in The VETTDD Briefing.