Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services.

Atlassian addressed the reported URL-based issue on the server side after responsible disclosure, with the fix deployed on July 8, 2026.

Rovo is Atlassian’s enterprise AI assistant, designed to search, summarize, and take actions across Jira, Confluence, Bitbucket, and third-party SaaS platforms.

Its value comes from access to organizational context. However, the same broad access can create a major security risk when attacker-controlled content is treated as trusted instructions.

The RovoBlast attack abused a URL parameter named rovoChatPrompt. This parameter could pre-fill Rovo Chat with a prompt when a signed-in user opened a specially crafted link.

Atlassian Rovo Prompt Injection Flaw

According to Varonis, the assistant processed the supplied text within the victim’s authenticated session, effectively giving the attacker the same context and access available to the user.

The attack did not require a jailbreak, stolen credentials, or a demonstrated permission bypass. Instead, it relied on parameter-to-prompt injection, also called P2P injection.

A victim only needed to click a malicious link while signed in to Atlassian. Rovo could then search data sources that the victim was already authorized to access and summarize the results.

This distinction is important. RovoBlast did not grant an attacker unrestricted access to an entire Atlassian tenant. The signed-in user’s existing permissions limited the exposed data.

Still, many employees can access confidential Jira tickets, internal Confluence pages, API keys, project plans, customer records, and incident-response documentation. A single compromised session could therefore expose valuable business information.

Varonis researchers reported that Rovo’s autonomous capabilities increased the impact. Rovo’s ResearchAgent can perform multi-step research and browsing tasks.

In an unsafe prompt-injection scenario, such features may enable an AI assistant to retrieve internal content, transform it, and communicate it to an external destination with little additional user interaction.

The finding highlights a broader enterprise AI security challenge. AI assistants increasingly combine access to private data, exposure to untrusted content, and the ability to use external tools or websites. This combination can turn an ordinary link, document, comment, or connected application into an entry point for instruction injection.

Security teams should treat AI assistants as privileged access layers rather than simple chat interfaces. Organizations should review Rovo permissions, disconnect unused connectors, and restrict access to highly sensitive repositories such as legal, HR, finance, and security incident records.

They should also limit agentic browsing and automation capabilities where those features are not operationally necessary.

Monitoring is equally important.

Teams should review AI activity logs, investigate unusual agent runs, and test whether external inputs can influence AI behavior in their environment. User awareness training should also cover malicious links and AI-enabled phishing scenarios.

RovoBlast demonstrates that enterprise AI risk is not only about model behavior. It is about trust boundaries. When an AI assistant can read sensitive data, impersonate a legitimate user, and interact with external services, a single misclassified input can lead to silent data exposure.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.