Rovo can be steered into leaking Jira and Confluence data that the signed-in user already has access to. The weak point is not the chat window itself. It is any attacker-controlled content or link that gets the assistant to treat hostile text as instructions and then use the user's own workspace access to fetch and send data off-box.
Two independent firms found that path. PromptArmor said concealed instructions in content could make Rovo pull internal data and send it out through a URL request, even with web search switched off; Varonis found a separate link-based preload through the rovoChatPrompt parameter that ran with the user's privileges, and Atlassian fixed that server-side on July 8, 2026.
The containment gap is broader than a single setting. If an AI assistant can read internal docs or tickets and follow attacker-supplied content or URLs, disabling web search is not enough; the real boundary is whatever the signed-in user can already see in Jira and Confluence.