Skip to content
promptarmor.com·

🔒Atlassian's Rovo AI Vulnerable to Data Exfiltration

Your Atlassian data is at risk from a sneaky new attack vector

TL;DR

PromptArmor disclosed a critical vulnerability in Atlassian's Rovo AI, allowing attackers to exfiltrate sensitive data without human intervention. The flaw remains unpatched despite multiple follow-ups.

PromptArmor has exposed a significant security flaw in Atlassian's Rovo AI that enables attackers to steal data across an entire tenant without needing direct user interaction. This vulnerability allows for indirect prompt injection, which can bypass existing controls and exfiltrate any data accessible by Rovo, including data from 'connectors'. The attack chain starts with a user uploading a file containing hidden prompts, leading to the submission of Jira tickets and Confluence documents to an attacker's website. Despite PromptArmor disclosing this issue on May 23rd, Atlassian has not provided further communication or fixed the vulnerability as of August 5th.

Atlassian's Rovo AI Vulnerable to Data Exfiltration — promptarmor.com

Key Points

1

PromptArmor reported a critical vulnerability in Atlassian's Rovo AI on May 23rd, 2026

2

The attack chain begins with users uploading files containing hidden prompt injections to Rovo

3

Rovo can submit Jira tickets and Confluence documents to an attacker-controlled website

4

Atlassian acknowledges the issue but has not provided any updates or patches since May 25th

5

A second exfiltration mechanism exists through insecure Markdown image rendering

Why It Matters

If you're using Atlassian's Rovo AI, your data is at risk from a new attack vector that bypasses existing security controls. The vulnerability allows attackers to exfiltrate sensitive information without direct user interaction or approval. This affects teams relying on Jira and Confluence for project management and documentation.

AtlassianRovo AIdata securityvulnerabilityPromptArmor

Frequently Asked Questions

Why does this matter?

If you're using Atlassian's Rovo AI, your data is at risk from a new attack vector that bypasses existing security controls. The vulnerability allows attackers to exfiltrate sensitive information without direct user interaction or approval. This affects teams relying on Jira and Confluence for project management and documentation.

What happened?

PromptArmor disclosed a critical vulnerability in Atlassian's Rovo AI, allowing attackers to exfiltrate sensitive data without human intervention. The flaw remains unpatched despite multiple follow-ups.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,646 builders reading daily.

Also get