Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers — [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFYjJTxVoOMkR9D
What’s new: Atlassian’s Rovo assistant can be exploited to exfiltrate Jira and Confluence data to attackers. Two security firms discovered that Rovo can be tricked into sending data accessible to a signed-in user to an external server. One method, identified by PromptArmor, involves embedding malicious instructions in content that Rovo processes, while the other, termed RovoBlast by Varonis, uses a crafted URL parameter. The URL-based vulnerability was fixed on July 8, 2026, but the content-based method remains unconfirmed as resolved as of August 5, 2026.
Who’s affected
Organizations using Atlassian’s Rovo assistant, particularly those with Jira and Confluence integrations, are at risk. The vulnerabilities allow for data accessible to authenticated users to be sent to attacker-controlled servers.
What to do
- Review and restrict Rovo access for apps and user groups within your organization.
- Tighten permissions for connected third-party applications to limit data exposure.
- Disable Rovo features for specific apps if not needed, especially in Standard, Premium, and Enterprise plans.
- Monitor for any unusual data access patterns and ensure that the web-search toggle is not treated as a complete security measure.



