Salesforce Agentforce Flaws Expose Sensitive Data to Zero-Click Theft
Zenity Labs, a cybersecurity firm, has uncovered a set of three security vulnerabilities in Salesforce's Agentforce that could allow a malicious actor to exfiltrate sensitive CRM data without any user interaction.
The flaws, dubbed SalesBleed, enable zero-click data theft and AI agent impersonation. Two of the vulnerabilities use different exploitation techniques but reach the same result: sensitive Salesforce data can be transmitted outside the organization despite security controls intended to prevent communication with untrusted destinations.
Zenity Labs found multiple weaknesses in Trusted URLs, a mechanism designed to restrict external destinations Agentforce can access and redact links or images pointing to unapproved domains. The researchers demonstrated that these weaknesses could be abused to send sensitive data to unapproved destinations.