SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce

Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Table of Contents
    Add a header to begin generating the table of contents

    Security researchers disclosed a set of vulnerabilities dubbed SalesBleed in Salesforce Agentforce on September 24, 2026, that allowed zero-click theft of customer relationship management data and enabled anonymous phishing attacks through the platform. The flaws affected Salesforce’s AI agent platform for customer engagement, with researchers describing consequences as “very unexpected” for a cloud CRM system that stores sensitive customer and business data for millions of organizations.

    Zero-Click CRM Data Theft Without Authentication

    The SalesBleed vulnerabilities allowed attackers to steal CRM data from Salesforce customers without requiring authentication or user interaction. Zero-click exploitation means victims did not need to click a malicious link, open an attachment, or take any action—the attacker could extract data simply by targeting vulnerable Agentforce instances with no participation from the targeted organization.

    CRM systems store customer contact information, deal pipelines, communication histories, and often proprietary business intelligence about client relationships and sales strategies. Zero-click access to this data gives attackers everything needed for business email compromise, competitive intelligence theft, or targeted social engineering campaigns. The lack of authentication barriers compounds the severity, as it removes the need for attackers to first compromise valid Salesforce credentials or trick users into granting access.

    Anonymous Phishing Attacks via Salesforce Agentforce

    Beyond data theft, the SalesBleed flaws enabled attackers to launch phishing campaigns through Agentforce without authentication. This capability allows attackers to send emails or messages that appear to originate from legitimate Salesforce-powered customer engagement systems, lending credibility to phishing lures that recipients might otherwise recognize as suspicious.

    Phishing attacks launched through a victim organization’s own Salesforce instance can bypass email authentication controls like SPF, DKIM, and DMARC because the messages genuinely originate from Salesforce infrastructure associated with the target’s domain. Recipients see sender addresses and branding consistent with legitimate customer communications, making it far more difficult to distinguish phishing from real outreach.

    Salesforce Notification and Customer Patching Requirements

    Salesforce was notified of the SalesBleed vulnerabilities, and the disclosure indicates patches or mitigations should be available. The disclosure timeline and whether Salesforce issued a formal security advisory were not detailed, but customers running Agentforce should immediately apply any released patches and review access controls to verify no unauthorized data access occurred while the vulnerabilities were exploitable.

    Organizations should also audit Agentforce logs for signs of zero-click data extraction or unauthorized message sending. Given the severity of the flaws and the lack of authentication requirements, any exploitation would leave minimal evidence since attackers did not need to use compromised accounts or trigger user-visible actions.

    “Very Unexpected Consequences” and the Expanding SaaS Attack Surface

    Researchers characterized the SalesBleed impact as leading to “very unexpected consequences,” a phrasing that suggests the vulnerabilities enabled exploitation paths the Agentforce platform was not designed to prevent. This language often signals security assumptions embedded in the platform’s architecture that turned out to be incorrect—for example, assuming certain API endpoints were unreachable without authentication or that data queries would always enforce proper access controls.

    Salesforce Agentforce represents the expanding category of AI-powered customer engagement platforms that integrate deeply with CRM data to automate interactions. These platforms handle sensitive data at scale and interact with customers directly, creating high-value targets for attackers. The SalesBleed disclosure highlights the risk that AI agent platforms, built rapidly to capitalize on generative AI capabilities, may not have undergone the same security hardening as older, more established SaaS products.

    For Salesforce customers, the incident points to the need for defense-in-depth even within trusted SaaS platforms. Treating CRM data as if it could be exposed through zero-click flaws means implementing data classification, minimizing what sensitive information is stored in the CRM, and monitoring for unusual data access patterns that might indicate exploitation of unknown vulnerabilities—all measures that remain relevant even after Salesforce patches the disclosed SalesBleed flaws.

    Related Posts