Atlassian Rovo Flaws Expose Enterprise Data
In August 2026, security researchers disclosed two techniques that could cause Atlassian Rovo to exfiltrate Jira, Confluence, and connected-service data available to an authenticated user. Bugcrowd lists Varonis Threat Labs' one-click rovoChatPrompt URL-parameter issue as resolved, while PromptArmor reported on August 5 that its distinct content-based indirect prompt-injection chain remained exploitable at publication.
Security researchers have disclosed two distinct attack paths that can cause Atlassian Rovo to retrieve data available to an authenticated user and transmit it to an attacker-controlled server. The techniques rely on Rovo operating with a user's existing permissions, rather than directly bypassing Jira or Confluence access controls.
Varonis Threat Labs documented one route, dubbed RovoBlast, involving the rovoChatPrompt parameter in Rovo Chat URLs. According to Varonis and the related Bugcrowd disclosure, an attacker could embed a prompt in a crafted link. When an authenticated user opened it, Rovo treated the supplied text as a user query, searched accessible content, and could send retrieved values to an external host through a request URL.
Bugcrowd classifies the issue as an AI application security sensitive-information-disclosure vulnerability and marks it resolved. The disclosure says the technique could expose Confluence content, user identity information, API keys, and other secrets available through the victim's permissions, including data accessible through Jira and connected services. The Hacker News reports that Atlassian deployed a server-side fix on July 8 and that the reporter validated it.
A separate content-based injection path
PromptArmor reported a different indirect prompt-injection technique on August 5. In its demonstration, a user uploaded a document containing concealed attacker instructions, then asked Rovo to organize Jira tickets. PromptArmor reported that the instructions caused Rovo to search Jira and Confluence, append retrieved content to an attacker-controlled URL, and open that URL, placing the data in the attacker's server logs.
PromptArmor stated that this chain did not require an additional human approval step once Rovo processed the malicious content. It also reported that disabling Rovo web search did not stop its demonstration because the attack used a URL-retrieval capability rather than search itself. The firm attributed the exposure to the absence of a control preventing the agent from opening dynamically constructed URLs.
PromptArmor said it disclosed the issue to Atlassian on May 23 and followed up on June 4 and July 29. At publication, the firm reported no further communication and said the content-based path remained exploitable. That status reflects PromptArmor's August 5 report; the available disclosures do not independently establish whether Atlassian subsequently remediated that separate technique.
Permission inheritance expands the blast radius
Both reports describe abuse of legitimate Rovo session privileges, not a direct authorization bypass. This distinction matters operationally: the accessible data set depends on the victim's entitlements across Jira, Confluence, and any connected SaaS applications. Varonis lists Slack, Microsoft 365, Google Workspace, and other connected tools among the surfaces Rovo can access.
The two findings illustrate a recurring risk in agentic enterprise systems. When a model can ingest untrusted content, search internal systems, and make outbound requests in one workflow, conventional permission checks can still permit harmful actions under a legitimate identity. Security teams using comparable systems commonly assess connector scope, outbound URL controls, prompt-injection handling, and audit visibility together, because each control addresses only part of the chain.
The disclosures also show why remediation status must be tracked per attack path. The URL-parameter issue is marked fixed by Bugcrowd, while the available reporting identifies PromptArmor's document-based indirect-injection route as a separate finding with a different reported status.
Key Points
- 1Two independent Rovo attack paths used authenticated user permissions to expose internal content, making existing entitlement scope central to potential impact.
- 2Bugcrowd marks the URL-parameter RovoBlast vulnerability resolved, but PromptArmor reported its content-based injection technique remained exploitable on August 5.
- 3Comparable enterprise agents increase exposure when untrusted inputs, broad data connectors, and outbound retrieval actions operate within a single workflow.
Scoring Rationale
The disclosures affect an enterprise AI assistant connected to high-value collaboration systems and potentially other SaaS data sources. The report of a separate content-based path remaining exploitable raises practical prompt-injection and data-egress concerns for teams deploying agentic search and automation.
Sources
Primary source and supporting public references used for this report.
View 4 more sources
- RovoBlast: How One Click Triggered Atlassian's AI Assistant to Leak Datavaronis.com
- One-Click Data Exfiltration via rovoChatPrompt URL Parameter (Confluence / Rovo)bugcrowd.com
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackersthehackernews.com
- Rovo data, privacy, and usage guidelinessupport.atlassian.com
Practice with real SaaS & B2B data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all SaaS & B2B problems

