Close Menu
WithO2WithO2

    Subscribe to Updates

    Get the latest AI News Tools Updates in your Inbox

    What's Hot

    AI in Ecommerce: 9 Uses That Move Revenue

    September 20, 2026

    Anthropic CEO Calls for AI Speed Limits — What Business Buyers Should Know

    September 20, 2026

    GPT-6 Astra Launch: OpenAI’s Computer-Use AI, Pricing and Who Gets It

    September 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    WithO2WithO2
    • AI
    • Blog
    • Business Software
    • Trending News
    • Stories
    WithO2WithO2
    Home » Trending News
    Trending News

    Atlassian Rovo Has an Unpatched Data Leak Flaw After 2 Months

    By Amitabh SarkarAugust 10, 2026Updated:September 3, 20264 Mins Read7
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Ticket cards leaking from a project management board toward an external attacker server
    PromptArmor's disclosure shows Rovo's URL retrieval tool can silently exfiltrate Jira and Confluence data.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Atlassian’s Rovo AI assistant has an unpatched indirect prompt injection vulnerability that lets attackers silently exfiltrate Jira tickets, Confluence documents, and connected third-party data, security firm PromptArmor disclosed publicly on August 5, 2026 — more than two months after reporting the flaw to Atlassian on May 23.

    PromptArmor reported the vulnerability to Atlassian on May 23, 2026. Atlassian assigned a case number on May 25 and then made no further substantive communication despite PromptArmor follow-ups on June 4 and July 29. PromptArmor published full technical details on August 5 after exhausting its responsible disclosure process. Rovo is the AI assistant embedded by default across Atlassian Cloud products, including Jira Software, Confluence, and Jira Service Management. The attack is zero-click: exfiltration executes without any human approval step, and the chat history shows no visible trace.

    Table of Contents

    Toggle
    • How the Rovo Data Exfiltration Attack Works
    • What Atlassian Has and Has Not Fixed
    • What Atlassian Customers Should Do Now
    • Our Take
    • For Context
    • Related

    How the Rovo Data Exfiltration Attack Works

    The attack plants hidden prompt injection instructions inside a document that Rovo later processes — such as a vendor PDF uploaded to Confluence or a shared backlog guide. When any employee asks Rovo a question that touches the poisoned document, the injected instructions direct Rovo’s URL retrieval tool to send company data to an attacker-controlled server. PromptArmor documented a second exfiltration mechanism through Rovo’s Markdown image rendering, a standard prompt injection vector also seen in other AI assistants.

    The exposed data covers everything Rovo can access in an Atlassian tenant: Jira tickets, Confluence pages, and data pulled in from third-party connectors. According to PromptArmor, the attack succeeds even when an organization has disabled web search for Rovo: “This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.”

    What Atlassian Has and Has Not Fixed

    Atlassian fixed a separate, less severe Rovo flaw in July 2026: a one-click exfiltration through the rovoChatPrompt URL parameter, disclosed via Bugcrowd in November 2025, rated P2, and rewarded with $6,000. The indirect prompt injection that PromptArmor describes remains unpatched as of August 5, 2026, and Atlassian has not publicly responded to it. PromptArmor stated: “Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable as of the release of this article.” PromptArmor’s research targets Atlassian Cloud; no evidence exists of exploitation in a real-world attack.

    What Atlassian Customers Should Do Now

    Teams evaluating the Atlassian stack against other options for choosing project management software now have a concrete security criterion: audit which AI agents hold access to which data stores before enabling them. Rovo is included in standard Atlassian Cloud subscriptions, so many organizations have it active without an explicit opt-in. Three immediate steps: inventory the Confluence spaces and Jira projects Rovo can read, restrict Rovo’s access to sensitive spaces, and treat externally sourced documents, such as vendor PDFs and shared templates, as untrusted input until Atlassian ships a patch.

    Our Take

    Atlassian shipped Rovo into every Cloud subscription and left its AI governance controls in an admin panel most teams never open — and the one control that promises to reduce leakage, disabling web search, does not close the hole. The disclosure pattern matters as much as the flaw: PromptArmor previously demonstrated comparable exfiltration paths in Microsoft Copilot and Slack AI, which makes embedded enterprise AI assistants a recurring attack surface, not a one-off bug. Enterprise AI is a security decision before it is a productivity decision, and buyers should demand a documented prompt-injection posture from every vendor whose agent touches company data.


    For Context

    Enterprise software vendors spent 2026 embedding AI agents directly into their core products, and security evaluation has lagged adoption. AI agents embedded in business software now transact and act autonomously, while AI governance obligations for businesses already carry legal force in the EU. The Rovo disclosure adds unpatched vulnerability risk to that evaluation checklist.

    Related

    • 12 Best Project Management Software Tools — how Atlassian’s Jira compares with alternatives
    • How AI agents work inside business tools — the tool-access model that makes attacks like this possible
    • How AI is reshaping CRM and project management tools — the market pressure driving vendors to ship AI fast

    Last Updated: August 2026

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Amitabh Sarkar
    • Website

    I am a software engineer, I have a passion for working with cutting-edge technologies and staying up-to-date with the latest developments in the field. In my articles, I share my knowledge and insights on a range of topics, including business software, how to set up tools, and the latest trends in the tech industry.

    Related Posts

    Anthropic CEO Calls for AI Speed Limits — What Business Buyers Should Know

    September 20, 2026

    GPT-6 Astra Launch: OpenAI’s Computer-Use AI, Pricing and Who Gets It

    September 17, 2026

    Yoshua Bengio Explains Why AI Agents Cheat: Claude 4 Blackmail and 15,000 Wiki Edits

    September 17, 2026

    Comments are closed.

    Don't Miss
    AI

    AI in Ecommerce: 9 Uses That Move Revenue

    By Amitabh SarkarSeptember 20, 2026

    AI in ecommerce is the application of machine learning and large language models to automate…

    Anthropic CEO Calls for AI Speed Limits — What Business Buyers Should Know

    September 20, 2026

    GPT-6 Astra Launch: OpenAI’s Computer-Use AI, Pricing and Who Gets It

    September 17, 2026

    Yoshua Bengio Explains Why AI Agents Cheat: Claude 4 Blackmail and 15,000 Wiki Edits

    September 17, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Our Picks

    Workflow Automation Software: How to Choose the Right Tool

    September 11, 2026

    Shopify vs WooCommerce vs BigCommerce 2026: Which Platform Wins?

    August 31, 2026

    12 Best Project Management Software Tools in 2026

    August 1, 2026

    9 Best Ecommerce Platforms Compared (2026)

    July 30, 2026
    Editors Picks

    Anthropic CEO Calls for AI Speed Limits — What Business Buyers Should Know

    September 20, 2026

    GPT-6 Astra Launch: OpenAI’s Computer-Use AI, Pricing and Who Gets It

    September 17, 2026

    Yoshua Bengio Explains Why AI Agents Cheat: Claude 4 Blackmail and 15,000 Wiki Edits

    September 17, 2026

    Insurance Broker CRM in 2027: What AI Must Do for Benefits Teams

    September 15, 2026
    About Us
    About Us

    Your Source for Innovation: Discover in-depth guides, solutions, and tools tailored to modern business challenges.

    Links
    • Blog
    • Privacy Policy
    • Contact WithO2.com
    • Terms and Conditions
    Facebook X (Twitter) Instagram Pinterest
    • About
    • Editorial Policy
    • Contact
    • Privacy Policy
    • Terms
    © 2026 WITHO2.COM

    Type above and press Enter to search. Press Esc to cancel.