Atlassian Rovo Vulnerability Exposes Jira and Confluence Data to Attackers

A recently identified vulnerability in Atlassian's Rovo assistant allows attackers to extract data from Jira and Confluence. While one exploit path has been confirmed closed, the status of another remains uncertain.

A vulnerability in Atlassian’s Rovo assistant has been discovered, enabling attackers to manipulate the assistant into collecting data from Jira and Confluence that a signed-in user can access. This data can then be sent to an external server without the user’s explicit approval. Two security firms independently identified this issue, though only one of the identified routes has been confirmed as closed.

Details of the Vulnerability

PromptArmor, an AI security firm, reported that by embedding attacker-controlled instructions within content that Rovo processes, they could make the assistant gather internal data. This was achieved simply by uploading a file, which prompted Rovo to send the information through a URL request. The firm confirmed this behavior on August 5, 2026, noting that the exploit still functioned even when Rovo’s web-search feature was disabled. However, the status of a later remediation for this issue remains unconfirmed.

Alternative Attack Vector Identified

Varonis Threat Labs discovered a different method, termed RovoBlast, where attacker instructions could be preloaded into Rovo Chat via the rovoChatPrompt URL parameter. This allowed a single click from an authenticated user to execute the attack, sending data to an attacker-controlled server. Varonis disclosed this issue through Bugcrowd, which indicates that Atlassian addressed it server-side on July 8, 2026, and the fix has been validated.

Implications for Users

Neither of the reported vulnerabilities has been assigned a CVE identifier, and as of August 8, 2026, no entries for these issues were found in the NVD or CISA’s Known Exploited Vulnerabilities catalog. The vulnerabilities primarily affect data that the signed-in user can access, rather than allowing a broader tenant-wide authorization bypass. Rovo is enabled by default for users on Standard, Premium, and Enterprise plans, meaning that organizations must actively manage permissions to mitigate risks.

Mitigation Strategies

Organizations can limit Rovo’s access by reviewing which apps and groups are permitted to use it, tightening underlying permissions, and avoiding reliance on the web-search toggle as a comprehensive security measure. While the link-based vulnerability has been resolved, the content-borne risk remains unaddressed, and organizations should remain vigilant regarding how Rovo interacts with their data.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 350