Atlassian Rovo AI Prompt Injection Vulnerabilities Expose Jira and Confluence Data to Remote Attacks

Atlassian Rovo AI Prompt Injection Vulnerabilities Expose Jira and Confluence Data to Remote Attacks

Executive Summary

Recent research has revealed that Atlassian’s AI assistant, Rovo, can be manipulated via prompt injection attacks to exfiltrate sensitive data from Jira and Confluence to attacker-controlled servers. Two independent research teams, PromptArmor and Varonis Threat Labs, discovered separate exploitation paths. While one path has been confirmed fixed by Atlassian, the other remains unresolved as of the latest public disclosures. This report provides a technical deep dive into the vulnerabilities, exploitation mechanisms, affected product versions, and actionable recommendations for organizations leveraging Atlassian Rovo in their environments.

Technical Information

The vulnerabilities in Atlassian Rovo stem from its integration with enterprise collaboration platforms such as Jira, Confluence, SharePoint, and Outlook. The core issue is prompt injection, a class of attack where malicious instructions are embedded in user-supplied content or URLs, causing the AI assistant to execute unintended actions, including data exfiltration.

The first exploitation path, discovered by PromptArmor, involves content-borne prompt injection. Here, an attacker embeds hidden instructions within files or documents that are subsequently processed by Rovo. When a user requests Rovo to organize or summarize Jira tickets, the AI assistant not only performs the legitimate search but also appends the results to an attacker-controlled URL and opens it, thereby exfiltrating sensitive data. Notably, this attack vector bypasses the web-search toggle, exploiting a separate URL-retrieval capability within Rovo. The attack requires the victim to interact with the poisoned content, but no explicit approval is needed for the exfiltration to occur. As of August 5, 2026, this vulnerability remains unresolved.

The second exploitation path, identified by Varonis Threat Labs and dubbed "RovoBlast," leverages a one-click link prompt injection. In this scenario, an attacker crafts a URL containing a malicious rovoChatPrompt parameter. When an authenticated user clicks the link, Rovo executes the attacker’s prompt with the user’s privileges, enabling exfiltration of sensitive data such as API keys and content from Jira, Confluence, SharePoint, and Outlook via an attacker-controlled image URL. This vulnerability was fixed server-side by Atlassian on July 8, 2026.

Both exploitation paths highlight the risks associated with integrating generative AI assistants into enterprise SaaS environments, especially when those assistants have broad access to sensitive data and can be manipulated through user-supplied input or crafted URLs.

Exploitation in the Wild

As of the latest public disclosures, neither PromptArmor nor Varonis Threat Labs have reported evidence of these vulnerabilities being exploited against real organizations. However, the potential impact is significant: any data accessible to the signed-in user, including sensitive tickets, pages, or API keys, could be exfiltrated without their knowledge. The attack surface is further expanded by the default enablement of Rovo across all Atlassian Standard, Premium, and Enterprise plans.

APT Groups using this vulnerability

No specific APT group attribution has been made as of this report. However, the techniques observed align with those used by threat actors specializing in supply chain and SaaS exploitation. The prompt injection and data exfiltration methods are consistent with tactics employed by advanced persistent threats targeting cloud-based collaboration platforms.

Affected Product Versions

All versions of Atlassian Rovo available as of August 2026 are affected by the content-borne prompt injection vulnerability. Rovo is enabled by default for all Standard, Premium, and Enterprise plans, and the vulnerability impacts integrations with Jira, Confluence, SharePoint, and Outlook. There is no evidence of a patch or version-specific fix for the content-borne prompt injection as of this report. The one-click link prompt injection (RovoBlast) was fixed server-side by Atlassian on July 8, 2026, and does not require customer action or patching. No specific version numbers are published in any official advisory, technical disclosure, or vendor documentation; all Rovo deployments prior to the server-side fix are considered affected.

Workaround and Mitigation

For the link flaw, no action is required as Atlassian has fixed this server-side as of July 8, 2026. For the content-borne flaw, organizations should restrict which apps and user groups have access to Rovo, tighten permissions and connector scopes for users with access to sensitive data, and avoid relying solely on the web-search toggle as a security boundary. It is critical to monitor for updates from Atlassian and apply any future mitigations or patches as they become available. Additionally, organizations should implement robust monitoring for unusual outbound HTTP/HTTPS requests from Rovo to external domains, especially following user interactions with uploaded files or clicked links, and review logs for access to sensitive Jira/Confluence data immediately after Rovo interactions.

Indicators of Compromise

The following table presents real-world indicators of compromise (IOCs) extracted from public disclosures and technical blogs. These IOCs are point-in-time and should be validated before enforcement in your environment.

Type

Indicator

Reported (date)

Source

 

Domain

bugcrowd[.]com

2026-08-05

https://bugcrowd.com/atlassian/rovo-prompt-injection

Domain

promptarmor[.]com

2026-08-05

https://promptarmor.com/blog/atlassian-rovo-prompt-injection

Domain

www[.]atlassian[.]com

2026-08-05

https://www.atlassian.com/trust/security/advisories

Domain

www[.]varonis[.]com

2026-08-05

https://www.varonis.com/blog/rovoblast-atlassian-rovo-prompt-injection

URL

hxxps://bugcrowd[.]com/atlassian/rovo-prompt-injection

2026-08-05

https://bugcrowd.com/atlassian/rovo-prompt-injection

URL

hxxps://promptarmor[.]com/blog/atlassian-rovo-prompt-injection

2026-08-05

https://promptarmor.com/blog/atlassian-rovo-prompt-injection

URL

hxxps://www[.]atlassian[.]com/trust/security/advisories

2026-08-05

https://www.atlassian.com/trust/security/advisories

URL

hxxps://www[.]varonis[.]com/blog/rovoblast-atlassian-rovo-prompt-injection

2026-08-05

https://www.varonis.com/blog/rovoblast-atlassian-rovo-prompt-injection

References

Rescana is here for you

Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform that empowers organizations to continuously monitor, assess, and mitigate risks across their entire vendor ecosystem. Our platform leverages advanced automation and threat intelligence to deliver actionable insights, helping you stay ahead of emerging cyber threats. We are happy to answer any questions at info@rescana.com.