Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    August 9, 2026

    Forecasting the AI bubble: When scarcity turns to surplus

    August 9, 2026

    What AI model escapes mean for AI safety, according to Nate Soares

    August 8, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
    Cybersecurity

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    InfoForTechBy InfoForTechAugust 9, 2026No Comments6 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.

    PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was enough to make the assistant gather internal data and send it out through a URL request, with no separate approval step.

    The firm published on August 5, 2026 and said the chain still worked with Rovo’s web-search option switched off. That bypass is single-sourced, and the report establishes the finding’s status only on that date; a later remediation is not confirmed here.

    Varonis Threat Labs put the instructions in a link instead. It found that the rovoChatPrompt URL parameter would preload attacker instructions into Rovo Chat, so one click from an authenticated user was enough for Rovo to run them with that user’s privileges and send the results to an attacker-controlled server.

    Varonis calls the flaw RovoBlast and says it disclosed the issue through Bugcrowd. The Bugcrowd record shows Atlassian fixed it server-side on July 8, 2026, and the reporter validated the fix.

    Neither issue leaves customers a patch to apply: the link flaw was closed on Atlassian’s side, and the lever for the content-borne path is scoping which apps and groups can use Rovo at all.

    The file that carries orders

    The PromptArmor chain is an indirect prompt-injection attack: attacker-controlled text is placed inside content the assistant is asked to use, and the model treats some of that text as instructions.

    In the firm’s published example, a user uploads a document carrying a concealed injection and asks Rovo to organize their Jira tickets. Rovo searches Jira and Confluence as asked, appends what it finds to an attacker’s URL and opens it, and the attacker reads the ticket and page contents out of their own server logs.

    PromptArmor said a user returning to the chat later sees the suggested ticket updates and no sign of the exfiltration.

    The interaction is not cleanly described as zero-click. The victim still has to expose Rovo to the poisoned content and make a normal request. PromptArmor’s narrower claim is that the exfiltration step does not require a separate human-in-the-loop approval.

    The web-search finding matters because Atlassian offers web search as a separate organization-level setting that lets users expand Rovo’s sources to public websites. PromptArmor said disabling that option did not stop its chain, because the outbound request used a separate URL-retrieval capability.

    It put the root cause plainly: nothing checks whether the URL being opened was one the agent constructed itself. The report also notes Rovo renders Markdown images from model output, a second way data could leave, though it does not demonstrate a full chain through that route for Rovo. The web-search bypass remains attributed to PromptArmor rather than treated as independently reproduced.

    Atlassian’s page for that setting does not say whether a request the assistant composes and fetches on its own falls under the same control. That is the question the finding raises for anyone deciding what the toggle is worth.

    PromptArmor said it disclosed the issue to Atlassian on May 23, 2026, received a case number two days later, followed up on June 4 and again on July 29, and published after what it described as no further communication.

    The Hacker News found no post-publication update to that report as of August 8, 2026, and its text still describes Rovo as vulnerable at the time it went out. That was nearly a month after the July 8 fix landed, and neither disclosure says whether that change touched the content-borne path.

    The one-click link flaw is fixed

    The Bugcrowd disclosure gives the firmer record of the two, and Varonis has published a fuller account of the attack.

    The rovoChatPrompt parameter could carry a full prompt in a Rovo URL. The proof of concept told Rovo to locate information the victim could access, put it into the path of an attacker-controlled image URL and fetch the image. That request delivered the data to the attacker’s server.

    The reporter demonstrated exfiltration of a private API key from Confluence, and Bugcrowd says the same one-click technique was tested against Jira and data reachable through SharePoint and Outlook connectors.

    The report is rated P2 on Bugcrowd’s priority scale and drew a $6,000 bounty; Atlassian deployed the server-side fix on July 8, and the report is marked resolved.

    Neither disclosure carries a CVE identifier, and searches of NVD and CISA’s Known Exploited Vulnerabilities catalog returned none for either issue as of August 8, 2026.

    Permissions, and what can be switched off

    Rovo’s data access follows permissions configured in Atlassian products and connected third-party apps. The risk shown is therefore data the signed-in victim can reach, not a demonstrated tenant-wide authorization bypass.

    The demonstrations add a route for permitted data to leave, with the person holding those permissions never choosing to send it. That distinction should shape how the risk is scoped rather than shrink it: in an assistant deliberately wired across Atlassian products and connected third-party apps, the reach of a single account is the product working as intended.

    Rovo is on by default for apps on Standard, Premium, and Enterprise plans, and everyone in an organization can use its features, according to Atlassian’s documentation. Administrators are not limited to an all-or-nothing choice.

    Organizations can block Rovo features for supported apps, which disables current and upcoming AI features for that app, including Agents and Chat. Enterprise’s newer access experience can also manage Rovo by app and user group.

    Atlassian documents one caveat: on a site running several Jira-family apps, blocking one of them does not remove the shared capabilities. Rovo Search, Chat and Create with Rovo stay available as long as any Jira app on that site still has Rovo enabled.

    The link flaw is already fixed on Atlassian’s side, so the immediate response is narrower than it looks. For the separate content-borne risk, organizations can review which apps and groups have Rovo access, tighten underlying permissions and connector scope, and avoid treating the web-search toggle by itself as a complete security boundary.

    Neither disclosure reports evidence that either technique has been used against a real organization. That is a statement about what the two reports contain, not a finding that no such activity has occurred.

    One path is confirmed closed. PromptArmor said the other was unresolved when it published on August 5; its status after that date remains unconfirmed.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices

    August 8, 2026

    The CISO’s Guide to Catching Data Leaks Before They Hit ChatGPT and Other LLMs

    August 8, 2026

    Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

    August 8, 2026

    15 AI Security Lessons From Black Hat and Ai4 2026

    August 8, 2026

    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    August 7, 2026

    ChatGPT Atlas Shuts Down Aug. 9: What Users Must Save Before Migrating

    August 7, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026201 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026201 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.