Atlassian’s Rovo AI assistant has an unpatched indirect prompt injection vulnerability that lets attackers silently exfiltrate Jira tickets, Confluence documents, and connected third-party data, security firm PromptArmor disclosed publicly on August 5, 2026 — more than two months after reporting the flaw to Atlassian on May 23.
PromptArmor reported the vulnerability to Atlassian on May 23, 2026. Atlassian assigned a case number on May 25 and then made no further substantive communication despite PromptArmor follow-ups on June 4 and July 29. PromptArmor published full technical details on August 5 after exhausting its responsible disclosure process. Rovo is the AI assistant embedded by default across Atlassian Cloud products, including Jira Software, Confluence, and Jira Service Management. The attack is zero-click: exfiltration executes without any human approval step, and the chat history shows no visible trace.
How the Rovo Data Exfiltration Attack Works
The attack plants hidden prompt injection instructions inside a document that Rovo later processes — such as a vendor PDF uploaded to Confluence or a shared backlog guide. When any employee asks Rovo a question that touches the poisoned document, the injected instructions direct Rovo’s URL retrieval tool to send company data to an attacker-controlled server. PromptArmor documented a second exfiltration mechanism through Rovo’s Markdown image rendering, a standard prompt injection vector also seen in other AI assistants.
The exposed data covers everything Rovo can access in an Atlassian tenant: Jira tickets, Confluence pages, and data pulled in from third-party connectors. According to PromptArmor, the attack succeeds even when an organization has disabled web search for Rovo: “This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.”
What Atlassian Has and Has Not Fixed
Atlassian fixed a separate, less severe Rovo flaw in July 2026: a one-click exfiltration through the rovoChatPrompt URL parameter, disclosed via Bugcrowd in November 2025, rated P2, and rewarded with $6,000. The indirect prompt injection that PromptArmor describes remains unpatched as of August 5, 2026, and Atlassian has not publicly responded to it. PromptArmor stated: “Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable as of the release of this article.” PromptArmor’s research targets Atlassian Cloud; no evidence exists of exploitation in a real-world attack.
What Atlassian Customers Should Do Now
Teams evaluating the Atlassian stack against other options for choosing project management software now have a concrete security criterion: audit which AI agents hold access to which data stores before enabling them. Rovo is included in standard Atlassian Cloud subscriptions, so many organizations have it active without an explicit opt-in. Three immediate steps: inventory the Confluence spaces and Jira projects Rovo can read, restrict Rovo’s access to sensitive spaces, and treat externally sourced documents, such as vendor PDFs and shared templates, as untrusted input until Atlassian ships a patch.
Our Take
Atlassian shipped Rovo into every Cloud subscription and left its AI governance controls in an admin panel most teams never open — and the one control that promises to reduce leakage, disabling web search, does not close the hole. The disclosure pattern matters as much as the flaw: PromptArmor previously demonstrated comparable exfiltration paths in Microsoft Copilot and Slack AI, which makes embedded enterprise AI assistants a recurring attack surface, not a one-off bug. Enterprise AI is a security decision before it is a productivity decision, and buyers should demand a documented prompt-injection posture from every vendor whose agent touches company data.
For Context
Enterprise software vendors spent 2026 embedding AI agents directly into their core products, and security evaluation has lagged adoption. AI agents embedded in business software now transact and act autonomously, while AI governance obligations for businesses already carry legal force in the EU. The Rovo disclosure adds unpatched vulnerability risk to that evaluation checklist.
Related
- 12 Best Project Management Software Tools — how Atlassian’s Jira compares with alternatives
- How AI agents work inside business tools — the tool-access model that makes attacks like this possible
- How AI is reshaping CRM and project management tools — the market pressure driving vendors to ship AI fast