Atlassian Rovo Security Update Covers One Click Data Exposure While Prompt Injection Risk Remains Under Review

Published:

Atlassian has addressed one of two recently disclosed security issues affecting its AI assistant Rovo, while a separate report describing a prompt injection technique remains unresolved based on publicly available information. The findings relate to the possibility of attacker controlled instructions causing Rovo to access information from Jira and Confluence that an authenticated user is permitted to view and transmit that information to an external server. The two disclosures were published independently by PromptArmor and Varonis Threat Labs, each describing a different attack method. While Atlassian has confirmed a server side fix for the link based vulnerability reported by Varonis, the status of the content based prompt injection technique described by PromptArmor remains unconfirmed after its publication.

PromptArmor explained that its research focused on an indirect prompt injection attack in which malicious instructions are embedded within content processed by Rovo. According to the firm, a specially prepared file containing hidden instructions could influence the AI assistant after a user uploaded the document and requested a normal task such as organizing Jira tickets. PromptArmor stated that Rovo could then search Jira and Confluence for information available to the signed in user, append the collected data to an attacker controlled URL, and retrieve that address without requiring a separate approval step from the user. The firm also reported that this behavior continued even when Rovo web search was disabled, suggesting that the outbound request relied on a different URL retrieval capability. PromptArmor further noted that Rovo renders Markdown images generated by the model, identifying another possible route through which information could potentially leave an environment, although it did not demonstrate a complete attack chain using that method. The company disclosed the issue to Atlassian on May 23, 2026, received acknowledgement two days later, followed up in June and July, and published its findings on August 5 after stating that no additional communication had been received. As of August 8, the report continued to describe the content based technique as unresolved, while no confirmation had been provided regarding whether Atlassian’s earlier security update also addressed that specific issue.

A separate investigation conducted by Varonis Threat Labs identified a different vulnerability known as RovoBlast. Instead of embedding malicious instructions within uploaded content, the researchers used the rovoChatPrompt URL parameter to preload attacker controlled prompts into Rovo Chat. According to the disclosure, a single click by an authenticated user on a crafted link was sufficient for Rovo to execute those instructions using the permissions already assigned to that user. The proof of concept demonstrated how information from Confluence, Jira, SharePoint, and Outlook connectors could be gathered and transmitted to an external server. Varonis disclosed the issue through Bugcrowd, where the report received a P2 severity rating and a bounty of six thousand dollars. Bugcrowd records show Atlassian implemented a server side fix on July 8, 2026, and the researcher later confirmed the vulnerability had been resolved. Neither the PromptArmor report nor the Varonis disclosure references a CVE identifier, and no listing for either issue was available in the National Vulnerability Database or CISA Known Exploited Vulnerabilities catalog as of August 8, 2026.

According to Atlassian documentation, Rovo follows the same permission model already configured for Jira, Confluence, and connected third party applications, meaning the assistant can only access information that the signed in user is already authorized to view. The disclosed techniques therefore do not describe a tenant wide authorization bypass but instead demonstrate methods through which permitted information could potentially be transmitted outside an organization without the user’s intention. Rovo is enabled by default for organizations using Standard, Premium, and Enterprise plans, although administrators can restrict access by application or user group depending on their deployment. Atlassian also notes that disabling one Jira application does not necessarily remove shared Rovo capabilities if another supported Jira application remains active on the same site. At present, the one click link based vulnerability has been confirmed as resolved through Atlassian’s server side update, while organizations reviewing the separate PromptArmor findings may consider limiting Rovo access, tightening application permissions, reviewing connector scope, and monitoring AI assistant usage as additional precautions. Neither disclosure reported evidence that either technique had been exploited against real organizations, and the publicly available reports only document proof of concept demonstrations conducted by the researchers.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img