Recent findings have revealed a vulnerability in Atlassian’s Rovo assistant that allows attacker-controlled instructions to extract data from Jira and Confluence. This issue was independently discovered by two security firms, with only one of the identified attack vectors confirmed as resolved.
According to reporting by The Hacker News, PromptArmor, an AI security firm, demonstrated that simply uploading a file could enable Rovo to gather internal data and send it to an external server without requiring additional user approval. This vulnerability was published on August 5, 2026, and was reported to still function even when Rovo’s web-search feature was disabled.
Details of the Vulnerability
Varonis Threat Labs identified a different method, termed RovoBlast, where the rovoChatPrompt URL parameter could preload malicious instructions into Rovo Chat. This allowed an authenticated user to execute the commands with their own privileges, resulting in data being sent to an attacker-controlled server. Varonis disclosed this issue through Bugcrowd, and Atlassian reportedly fixed it server-side on July 8, 2026.
Mechanisms of Data Exfiltration
The PromptArmor vulnerability is characterized as an indirect prompt-injection attack, where malicious text is embedded in content that Rovo processes. For instance, a user could upload a document containing hidden instructions and request Rovo to organize Jira tickets. Rovo would then append the retrieved data to an attacker’s URL, allowing the attacker to access sensitive information.
While the interaction is not classified as zero-click, as the victim must still expose Rovo to the malicious content, the exfiltration does not require separate user approval. The web-search capability of Rovo, which allows it to access public websites, does not mitigate this risk, as the outbound requests can still occur through other means.
Current Status and Recommendations
Atlassian has stated that the link vulnerability has been addressed, but organizations are advised to review which applications and user groups have access to Rovo. Tightening permissions and connector scopes is recommended to prevent potential data leaks. As of now, there is no evidence that these vulnerabilities have been exploited in the wild.
One attack vector remains unresolved, and its status after the August 5 publication is still unclear.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


