Executive Summary
Recent research has revealed that Atlassian’s AI assistant, Rovo, can be manipulated via prompt injection attacks to exfiltrate sensitive data from Jira and Confluence to attacker-controlled servers. Two independent research teams, PromptArmor and Varonis Threat Labs, discovered separate exploitation paths. While one path has been confirmed fixed by Atlassian, the other remains unresolved as of the latest public disclosures. This report provides a technical deep dive into the vulnerabilities, exploitation mechanisms, affected product versions, and actionable recommendations for organizations leveraging Atlassian Rovo in their environments.
Technical Information
The vulnerabilities in Atlassian Rovo stem from its integration with enterprise collaboration platforms such as Jira, Confluence, SharePoint, and Outlook. The core issue is prompt injection, a class of attack where malicious instructions are embedded in user-supplied content or URLs, causing the AI assistant to execute unintended actions, including data exfiltration.
The first exploitation path, discovered by PromptArmor, involves content-borne prompt injection. Here, an attacker embeds hidden instructions within files or documents that are subsequently processed by Rovo. When a user requests Rovo to organize or summarize Jira tickets, the AI assistant not only performs the legitimate search but also appends the results to an attacker-controlled URL and opens it, thereby exfiltrating sensitive data. Notably, this attack vector bypasses the web-search toggle, exploiting a separate URL-retrieval capability within Rovo. The attack requires the victim to interact with the poisoned content, but no explicit approval is needed for the exfiltration to occur. As of August 5, 2026, this vulnerability remains unresolved.
The second exploitation path, identified by Varonis Threat Labs and dubbed "RovoBlast," leverages a one-click link prompt injection. In this scenario, an attacker crafts a URL containing a malicious rovoChatPrompt parameter. When an authenticated user clicks the link, Rovo executes the attacker’s prompt with the user’s privileges, enabling exfiltration of sensitive data such as API keys and content from Jira, Confluence, SharePoint, and Outlook via an attacker-controlled image URL. This vulnerability was fixed server-side by Atlassian on July 8, 2026.
Both exploitation paths highlight the risks associated with integrating generative AI assistants into enterprise SaaS environments, especially when those assistants have broad access to sensitive data and can be manipulated through user-supplied input or crafted URLs.
Exploitation in the Wild
As of the latest public disclosures, neither PromptArmor nor Varonis Threat Labs have reported evidence of these vulnerabilities being exploited against real organizations. However, the potential impact is significant: any data accessible to the signed-in user, including sensitive tickets, pages, or API keys, could be exfiltrated without their knowledge. The attack surface is further expanded by the default enablement of Rovo across all Atlassian Standard, Premium, and Enterprise plans.
APT Groups using this vulnerability
No specific APT group attribution has been made as of this report. However, the techniques observed align with those used by threat actors specializing in supply chain and SaaS exploitation. The prompt injection and data exfiltration methods are consistent with tactics employed by advanced persistent threats targeting cloud-based collaboration platforms.
Affected Product Versions
All versions of Atlassian Rovo available as of August 2026 are affected by the content-borne prompt injection vulnerability. Rovo is enabled by default for all Standard, Premium, and Enterprise plans, and the vulnerability impacts integrations with Jira, Confluence, SharePoint, and Outlook. There is no evidence of a patch or version-specific fix for the content-borne prompt injection as of this report. The one-click link prompt injection (RovoBlast) was fixed server-side by Atlassian on July 8, 2026, and does not require customer action or patching. No specific version numbers are published in any official advisory, technical disclosure, or vendor documentation; all Rovo deployments prior to the server-side fix are considered affected.
Workaround and Mitigation
For the link flaw, no action is required as Atlassian has fixed this server-side as of July 8, 2026. For the content-borne flaw, organizations should restrict which apps and user groups have access to Rovo, tighten permissions and connector scopes for users with access to sensitive data, and avoid relying solely on the web-search toggle as a security boundary. It is critical to monitor for updates from Atlassian and apply any future mitigations or patches as they become available. Additionally, organizations should implement robust monitoring for unusual outbound HTTP/HTTPS requests from Rovo to external domains, especially following user interactions with uploaded files or clicked links, and review logs for access to sensitive Jira/Confluence data immediately after Rovo interactions.
Indicators of Compromise
The following table presents real-world indicators of compromise (IOCs) extracted from public disclosures and technical blogs. These IOCs are point-in-time and should be validated before enforcement in your environment.
Type | Indicator | Reported (date) | Source
|
Domain | bugcrowd[.]com | 2026-08-05 | https://bugcrowd.com/atlassian/rovo-prompt-injection |
Domain | promptarmor[.]com | 2026-08-05 | https://promptarmor.com/blog/atlassian-rovo-prompt-injection |
Domain | www[.]atlassian[.]com | 2026-08-05 | https://www.atlassian.com/trust/security/advisories |
Domain | www[.]varonis[.]com | 2026-08-05 | https://www.varonis.com/blog/rovoblast-atlassian-rovo-prompt-injection |
URL | hxxps://bugcrowd[.]com/atlassian/rovo-prompt-injection | 2026-08-05 | https://bugcrowd.com/atlassian/rovo-prompt-injection |
URL | hxxps://promptarmor[.]com/blog/atlassian-rovo-prompt-injection | 2026-08-05 | https://promptarmor.com/blog/atlassian-rovo-prompt-injection |
URL | hxxps://www[.]atlassian[.]com/trust/security/advisories | 2026-08-05 | https://www.atlassian.com/trust/security/advisories |
URL | hxxps://www[.]varonis[.]com/blog/rovoblast-atlassian-rovo-prompt-injection | 2026-08-05 | https://www.varonis.com/blog/rovoblast-atlassian-rovo-prompt-injection |
References
- The Hacker News: Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
- SecurityWeek: Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data
- PromptArmor Disclosure
- Varonis Threat Labs: RovoBlast
- Bugcrowd Disclosure Record
- Atlassian Security Advisories
Rescana is here for you
Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform that empowers organizations to continuously monitor, assess, and mitigate risks across their entire vendor ecosystem. Our platform leverages advanced automation and threat intelligence to deliver actionable insights, helping you stay ahead of emerging cyber threats. We are happy to answer any questions at info@rescana.com.



