Vulnerabilities · 49 days ago
Rovo can be steered into leaking Jira and Confluence data that the signed-in user already has access to. The weak point is not the chat window itself. It is any attacker-controlled content or link that gets the assistant to treat hostile text as instructions and then use the user's own workspace access to fetch and send data off-box.
Two independent firms found that path. PromptArmor said concealed instructions in content could make Rovo pull internal data and send it out through a URL request, even with web search switched off; Varonis found a separate link-based preload through the rovoChatPrompt parameter that ran with the user's privileges, and Atlassian fixed that server-side on July 8, 2026.
The containment gap is broader than a single setting. If an AI assistant can read internal docs or tickets and follow attacker-supplied content or URLs, disabling web search is not enough; the real boundary is whatever the signed-in user can already see in Jira and Confluence.
3 sources covering this story
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Atlassian Rovo prompt injection can send Jira and Confluence data to attacker servers.
Part of the PlainSec briefing for 2026-08-10