
SalesBleed Turned a Public Web Form Into an Agentforce Data Leak
Zenity's SalesBleed let an anonymous Web-to-Lead submission make Agentforce leak company names and deal sizes with zero clicks. Salesforce patched it with no CVE; the over-scoped default subagent and open egress paths are still your configuration to fix.
September 26, 2026 · 10 min read