Atlassian’s Rovo assistant has been identified as a potential security risk, capable of leaking Jira and Confluence data to unauthorized servers. Two separate security firms have discovered that attacker-controlled instructions can manipulate Rovo to gather and transmit data accessible to a logged-in user. While one vulnerability has been addressed, the other remains an open concern.
Security Flaws Discovered
PromptArmor, a company specializing in AI security, uncovered a method whereby Rovo could be tricked into collecting and sending data without additional user consent. A file upload carrying hidden instructions could exploit Rovo’s capabilities to send data through a URL request. This flaw persists even when the web-search feature is disabled, as per PromptArmor’s findings published on August 5, 2026.
On the other hand, Varonis Threat Labs identified a flaw involving a URL parameter that preloads malicious instructions into Rovo Chat. A single click from an authenticated user could activate this vulnerability, allowing data to be sent to an attacker’s server. This issue, known as RovoBlast, was reported and subsequently patched on July 8, 2026.
Responses and Mitigations
Atlassian has addressed the link-based vulnerability server-side, preventing the exploit from being executed through a single-click mechanism. However, the content-related risk remains, with PromptArmor noting that disabling web search does not fully mitigate the issue. The responsibility now falls on organizations to manage Rovo’s permissions and access controls effectively.
PromptArmor disclosed their findings to Atlassian in May 2026, but as of their report’s publication, no further updates about a fix had been communicated. Varonis’s disclosure, verified through Bugcrowd, resulted in a $6,000 bounty for identifying the link flaw, emphasizing the importance of proactive vulnerability management.
Implications for Organizations
Organizations using Atlassian products are advised to reassess their security configurations, particularly concerning Rovo’s integration with other applications. Rovo’s permissions mirror those set in Jira and Confluence, meaning any data a user can access is potentially at risk. Companies should carefully consider which apps and groups have access to Rovo’s features and adjust permissions accordingly.
Although there is no evidence that these vulnerabilities have been exploited against real-world targets, the potential for data leaks remains a significant concern. By understanding and addressing these risks, organizations can better protect their sensitive information and ensure compliance with security best practices.
In conclusion, while Atlassian has made progress in securing Rovo, ongoing vigilance and management of permissions are crucial for minimizing exposure to data exfiltration risks.
