Atlassian’s Rovo AI assistant has been found vulnerable to attacks that can trick it into sending sensitive Jira and Confluence information to an attacker-controlled server. Two security firms independently discovered different ways to manipulate Rovo into performing these actions. The issue is linked to prompt injection, where hidden or attacker-controlled instructions can influence an AI system. The attacks do not appear to bypass the victim’s normal permissions, but they can misuse the access already available to that user.

atlassian-rovo-ai-assistant

The first attack path was discovered by AI security firm PromptArmor and involved an indirect prompt injection. Researchers placed hidden instructions inside content that Rovo was asked to process. In their demonstration, a user uploaded a document containing concealed instructions and asked Rovo to organize Jira tickets. Rovo then searched Jira and Confluence as part of the task, but the injected instructions caused it to collect information and send the results to an external server controlled by the attacker.

The hidden instructions could be placed inside a document in a way that would not be obvious to a normal user. PromptArmor demonstrated the technique using text hidden in a document, while other content sources could potentially also act as injection points. Once Rovo processed the malicious instructions, it could place information retrieved from Jira or Confluence into a specially created URL. Rovo then accessed that URL, allowing the information to reach the attacker’s server.

ai-prompt-injection-cyberattack

The researchers also found that disabling Rovo’s web-search feature did not necessarily prevent the attack. According to PromptArmor, Rovo had another capability that could retrieve information from URLs, and this could still be used to make an external request. This is important because simply turning off web search may not provide complete protection against every possible data-exfiltration technique. PromptArmor said the issue was reported to Atlassian on May 23, 2026, and later published its findings on August 5.

A separate attack was discovered by Varonis Threat Labs and was named RovoBlast. In this case, researchers found that a specially crafted Rovo URL could contain instructions that were loaded into Rovo Chat. When an authenticated user clicked the link, Rovo could process those instructions using the user’s existing permissions. The researchers demonstrated that information accessible to the user could then be placed into a request sent to an attacker-controlled server.

ai-agent-security-risk

Varonis reported that the RovoBlast technique could be used against information available through Confluence and Jira, as well as data connected through SharePoint and Outlook. Researchers demonstrated the extraction of a private API key stored in Confluence. The vulnerability was reported through Atlassian’s Bugcrowd program, and the disclosure record shows that Atlassian deployed a server-side fix on July 8, 2026. The reporter also validated that the fix worked.

There is an important limitation to the findings. The researchers did not demonstrate a complete permissions bypass that would allow an attacker to access every company’s data. Instead, the techniques could cause Rovo to collect information that the signed-in victim was already authorized to access. The security concern comes from turning those legitimate permissions into a way of moving data outside the organization without the user intentionally choosing to send it.

rovo-jira-confluence-data-leak

Atlassian users should therefore treat AI assistants with access to company information as an important security consideration. Organizations can review which applications and user groups have access to Rovo, reduce unnecessary permissions, and carefully control connected services. The RovoBlast URL-based issue has been confirmed as fixed, while the later status of the separate PromptArmor content-based attack was not confirmed in the available reporting. Neither disclosure reported evidence that these techniques had been used against a real organization.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news