Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Two independent findings showed that Atlassian’s Rovo assistant could be manipulated to collect Jira or Confluence data a signed-in user can access and send it to an attacker-controlled server. Varonis’ one-click link flaw, named RovoBlast, was fixed server-side on July 8, 2026, while PromptArmor’s content-borne injection path remained unconfirmed as of its August 5, 2026 report. #Rovo #RovoBlast #Atlassian #Jira #Confluence #Varonis #PromptArmor

Keypoints

  • Attacker-controlled instructions could make Rovo exfiltrate accessible Jira or Confluence data.
  • PromptArmor showed an indirect prompt-injection chain through uploaded content.
  • Varonis found the rovoChatPrompt URL parameter could preload malicious instructions into Rovo Chat.
  • Atlassian fixed the RovoBlast link flaw server-side on July 8, 2026.
  • Rovo access should be limited by app, group, permissions, and connector scope.

Read More: https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html