Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

The Hacker News by The Hacker News
August 8, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.

PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was enough to make the assistant gather internal data and send it out through a URL request, with no separate approval step.

The firm published on August 5, 2026 and said the chain still worked with Rovo’s web-search option switched off. That bypass is single-sourced, and the report establishes the finding’s status only on that date; a later remediation is not confirmed here.

Varonis Threat Labs put the instructions in a link instead. It found that the rovoChatPrompt URL parameter would preload attacker instructions into Rovo Chat, so one click from an authenticated user was enough for Rovo to run them with that user’s privileges and send the results to an attacker-controlled server.

Varonis calls the flaw RovoBlast and says it disclosed the issue through Bugcrowd. The Bugcrowd record shows Atlassian fixed it server-side on July 8, 2026, and the reporter validated the fix.

Neither issue leaves customers a patch to apply: the link flaw was closed on Atlassian’s side, and the lever for the content-borne path is scoping which apps and groups can use Rovo at all.

The file that carries orders

The PromptArmor chain is an indirect prompt-injection attack: attacker-controlled text is placed inside content the assistant is asked to use, and the model treats some of that text as instructions.

In the firm’s published example, a user uploads a document carrying a concealed injection and asks Rovo to organize their Jira tickets. Rovo searches Jira and Confluence as asked, appends what it finds to an attacker’s URL and opens it, and the attacker reads the ticket and page contents out of their own server logs.

PromptArmor said a user returning to the chat later sees the suggested ticket updates and no sign of the exfiltration.

The interaction is not cleanly described as zero-click. The victim still has to expose Rovo to the poisoned content and make a normal request. PromptArmor’s narrower claim is that the exfiltration step does not require a separate human-in-the-loop approval.

The web-search finding matters because Atlassian offers web search as a separate organization-level setting that lets users expand Rovo’s sources to public websites. PromptArmor said disabling that option did not stop its chain, because the outbound request used a separate URL-retrieval capability.

It put the root cause plainly: nothing checks whether the URL being opened was one the agent constructed itself. The report also notes Rovo renders Markdown images from model output, a second way data could leave, though it does not demonstrate a full chain through that route for Rovo. The web-search bypass remains attributed to PromptArmor rather than treated as independently reproduced.

Atlassian’s page for that setting does not say whether a request the assistant composes and fetches on its own falls under the same control. That is the question the finding raises for anyone deciding what the toggle is worth.

PromptArmor said it disclosed the issue to Atlassian on May 23, 2026, received a case number two days later, followed up on June 4 and again on July 29, and published after what it described as no further communication.

The Hacker News found no post-publication update to that report as of August 8, 2026, and its text still describes Rovo as vulnerable at the time it went out. That was nearly a month after the July 8 fix landed, and neither disclosure says whether that change touched the content-borne path.

The one-click link flaw is fixed

The Bugcrowd disclosure gives the firmer record of the two, and Varonis has published a fuller account of the attack.

The rovoChatPrompt parameter could carry a full prompt in a Rovo URL. The proof of concept told Rovo to locate information the victim could access, put it into the path of an attacker-controlled image URL and fetch the image. That request delivered the data to the attacker’s server.

The reporter demonstrated exfiltration of a private API key from Confluence, and Bugcrowd says the same one-click technique was tested against Jira and data reachable through SharePoint and Outlook connectors.

The report is rated P2 on Bugcrowd’s priority scale and drew a $6,000 bounty; Atlassian deployed the server-side fix on July 8, and the report is marked resolved.

Neither disclosure carries a CVE identifier, and searches of NVD and CISA’s Known Exploited Vulnerabilities catalog returned none for either issue as of August 8, 2026.

Permissions, and what can be switched off

Rovo’s data access follows permissions configured in Atlassian products and connected third-party apps. The risk shown is therefore data the signed-in victim can reach, not a demonstrated tenant-wide authorization bypass.

The demonstrations add a route for permitted data to leave, with the person holding those permissions never choosing to send it. That distinction should shape how the risk is scoped rather than shrink it: in an assistant deliberately wired across Atlassian products and connected third-party apps, the reach of a single account is the product working as intended.

Rovo is on by default for apps on Standard, Premium, and Enterprise plans, and everyone in an organization can use its features, according to Atlassian’s documentation. Administrators are not limited to an all-or-nothing choice.

Organizations can block Rovo features for supported apps, which disables current and upcoming AI features for that app, including Agents and Chat. Enterprise’s newer access experience can also manage Rovo by app and user group.

Atlassian documents one caveat: on a site running several Jira-family apps, blocking one of them does not remove the shared capabilities. Rovo Search, Chat and Create with Rovo stay available as long as any Jira app on that site still has Rovo enabled.

The link flaw is already fixed on Atlassian’s side, so the immediate response is narrower than it looks. For the separate content-borne risk, organizations can review which apps and groups have Rovo access, tighten underlying permissions and connector scope, and avoid treating the web-search toggle by itself as a complete security boundary.

Neither disclosure reports evidence that either technique has been used against a real organization. That is a statement about what the two reports contain, not a finding that no such activity has occurred.

One path is confirmed closed. PromptArmor said the other was unresolved when it published on August 5; its status after that date remains unconfirmed.



Source link

The Hacker News

The Hacker News

Next Post
How to Disable the AI Features in Gmail and Google Docs

How to Disable the AI Features in Gmail and Google Docs

Recommended.

Huawei Digital Finance приглашает партнеров принять активное участие в фестивале SFF 2025, продвигая интеллектуальную трансформацию в сфере международных финансов

Huawei Digital Finance приглашает партнеров принять активное участие в фестивале SFF 2025, продвигая интеллектуальную трансформацию в сфере международных финансов

November 18, 2025
One-time ‘SPAC King’ Palihapitiya launches new blank-check vehicle with plan to ‘temper’ retail fervor

One-time ‘SPAC King’ Palihapitiya launches new blank-check vehicle with plan to ‘temper’ retail fervor

September 30, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio