TechNewsReel
Live

Atlassian Rovo AI Flaw Allows Silent Exfiltration of Jira and Confluence Data

A critical indirect prompt injection vulnerability enables attackers to steal sensitive enterprise data via malicious PDF uploads.

TechNewsReel Newsroom · August 10, 2026

Security firm PromptArmor has uncovered a critical indirect prompt injection vulnerability in Atlassian’s Rovo AI assistant that allows attackers to silently exfiltrate sensitive corporate data. By embedding hidden instructions within uploaded files, such as PDFs, malicious actors can coerce the AI into sending internal documents to an external server without the user's knowledge.

The vulnerability enables the theft of any data the Rovo agent has permission to access within an Atlassian tenant, specifically targeting Jira tickets and Confluence documents. According to PromptArmor, the attack succeeds by manipulating Rovo to append sensitive internal data to a URL. The AI then uses its internal URL retrieval tool to "open" that link, which effectively logs the stolen data on a server controlled by the attacker. Notably, the attack remains effective even if an organization has disabled the "Enable web search" setting, as that toggle fails to remove the underlying tool used for opening search results.

The Mechanics of Indirect Injection

Indirect prompt injection occurs when an AI model processes external data—such as a webpage or a document—that contains hidden instructions designed to override the system's original programming. In enterprise environments, AI assistants like Rovo are granted extensive access to internal project management tools and documentation to provide utility to employees. This high level of access creates a dangerous vector if the AI can be tricked into treating a document's hidden text as a command to transmit data to an external endpoint.

Enterprise Security Implications

This flaw is particularly severe because it requires no human-in-the-loop approval and leaves no visible trace in the chat history for the victim. For enterprises that rely on Atlassian to store intellectual property and strategic project roadmaps, the ability for a single uploaded file to compromise an entire tenant's data represents a significant failure in AI input handling and tool-use permissions. PromptArmor stated that the attack "executes without requiring any human-in-the-loop approval, and succeeds by exploiting Rovo's URL retrieval tool."

Timeline and Current Status

PromptArmor disclosed the vulnerability to Atlassian on May 23, 2026. Despite follow-up communications on June 4 and July 29, the security firm reported that the flaw remained unpatched as of August 5, 2026. Organizations using Rovo AI should remain vigilant regarding the types of files uploaded to the system and monitor for unusual outbound requests, as the primary built-in defense mechanism for web search is currently ineffective against this specific exfiltration method.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.