Lab Exposes New Agentforce Data Exploit
Agentforce data breach needs no login. Zenity Labs found three chained vulnerabilities—Web-to-Lead form + DNS exfil—that bypass authentication entirely.

Why it matters
A critical agent security vulnerability in Salesforce's flagship agentic product exposes sensitive account data without user interaction or login. Practitioners deploying Agentforce in production need immediate clarity on patch status, affected versions, and compensating controls while this fix is pending.
The key facts
6 to knowThree chained vulnerabilities in Agentforce identified by Zenity Labs (AI agent security provider)
Attack path: Web-to-Lead form entry point + DNS query for data exfiltration
No authentication or user interaction required
Sensitive account data exposed
Vulnerability disclosure source: Zenity Labs (independent cybersecurity research, not Salesforce advisory)
Status: Article does not disclose patch status, timeline, affected versions, or CVSS score
Go to the source
Salesforce Bensalesforceben.com
Publisher excerpt: Cybersecurity experts discovered a way to pull sensitive account data from Agentforce without ever logging in or requiring the victim to click anything. A public Web-to-Lead form was used as the entry point, with a DNS query used as the exit. AI agent security provider Zenity Labs identified the…