Varonis discloses RovoBlast prompt-injection flaw in Atlassian Rovo AI

Varonis discloses RovoBlast prompt-injection flaw in Atlassian Rovo AI

Varonis says a fixed Atlassian Rovo flaw let a crafted link steer AI access to Jira, Confluence and SaaS data.

Format News Brief
Read Time 2 min
Category Cyber Security
Updated Aug 09, 2026

Security researchers at Varonis have disclosed a prompt-injection flaw in Atlassian Rovo that shows how enterprise AI assistants can turn ordinary user permissions into a data-exfiltration path. The issue, called RovoBlast, was published on August 7 and concerns Rovo Chat's handling of externally supplied prompt parameters inside a signed-in user's session.

According to Varonis, a crafted link could preload instructions through Rovo's chat URL parameters. If a user clicked it, Rovo could treat the attacker's text as trusted input, search the information that the user was already allowed to access, summarize it, and send it out through an attacker-controlled request. The researchers said the attack did not require a jailbreak, a permission bypass, or an additional confirmation prompt.

Why it matters

The disclosure is notable because Rovo is designed to connect knowledge across Atlassian products and third-party SaaS systems. Varonis says the assistant can work with Jira, Confluence, Bitbucket and connected tools such as Slack, Microsoft 365 and Google Workspace. In that model, the danger is not that the assistant gains forbidden access; it is that approved access can be steered by hostile instructions in a way the user did not intend.

SecurityWeek, citing the same research and related disclosures, reported that the one-click RovoBlast path was fixed server-side by Atlassian and that the Bugcrowd report was marked resolved. Varonis also says it responsibly disclosed the issue to Atlassian before publication. That should reduce immediate exposure for the specific URL-parameter path, but the broader lesson remains relevant for companies rolling out AI agents across internal data stores.

What teams should check

  • Review where Rovo and similar assistants are enabled, especially in environments with broad Confluence, Jira, email or file-sharing permissions.
  • Limit connector access to data that genuinely needs to be available to AI workflows.
  • Monitor assistant activity for unusual outbound fetches, automated browsing, or summaries of sensitive material.
  • Treat prompts, URL parameters, documents and web content as untrusted inputs even when they arrive inside a legitimate user session.

The RovoBlast report adds to a growing pattern in enterprise AI security: access control alone is not enough when agents can retrieve, transform and transmit information. Organizations need controls that distinguish between a user asking for data and an injected instruction trying to move that data somewhere else.

Sources

Cover photo by Brett Sayles on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...