Enterprise AI Security

Atlassian Rovo Security: CISO Guide to Prompt Injection

BT

BeyondScale Team

AI Security Team

12 min read

When Atlassian shipped Rovo, it gave enterprise teams a single AI assistant that reads across Jira, Confluence, Bitbucket, Slack, Google Workspace, and Microsoft 365 simultaneously. For security teams, that cross-system read access is the critical threat variable. Atlassian Rovo prompt injection does not touch one application: it touches your entire organizational knowledge graph.

In August 2026, two distinct prompt injection attacks against Rovo were publicly disclosed within days of each other. One was patched before publication. The other remained open for over two months with no response from Atlassian. Neither carries a CVE identifier. This guide covers both attacks, explains how Rovo's permission model amplifies blast radius, and gives you a concrete hardening checklist you can act on today.

Key Takeaways

    • RovoBlast (Varonis Threat Labs, DEF CON 34): a one-click URL parameter injection that seeded malicious instructions into any authenticated user's Rovo session and exfiltrated Jira, Confluence, and SharePoint content. Atlassian patched this on July 8, 2026. No CVE was assigned.
    • PromptArmor zero-click indirect injection: embedded in a document, no user interaction beyond uploading the file. Still unpatched at public disclosure on August 5, 2026, after two months of no substantive response from Atlassian.
    • Disabling Rovo's web search setting does NOT remove the URL retrieval tool used in exfiltration. The two capabilities are separate and only one is manageable through the admin console.
    • Rovo is bundled with Premium and Enterprise plans and cannot be fully uninstalled, making scoping and monitoring your primary risk controls rather than removal.
    • Blast radius is materially larger than any single-product AI assistant because Rovo holds read access across all connected systems simultaneously.
    • OWASP LLM Top 10 2026 ranks prompt injection at #1 and excessive agency at #3. Both apply directly to Rovo's architecture.

How Rovo's Permission Model Defines Blast Radius

Rovo operates on a permission-aware model: it surfaces only content the authenticated user is already authorized to see. Administrators enable connectors at the organization level. Each user then authorizes their own connection to each third-party app. Rovo uses those delegated credentials to search and synthesize across all connected sources in a single query.

This design decision is also the key threat variable. An engineer on your platform team with access to production incident tickets, the security runbook space in Confluence, and the on-call Slack channel exposes all three simultaneously through Rovo. A prompt injection that compromises that session can pull from all three sources in a single agent turn. There is no per-source query approval.

Default connector scope at most organizations includes: Jira (all projects the user can see), Confluence (all accessible spaces), Bitbucket (all accessible repositories), Slack, and at least one of Google Workspace or Microsoft 365. Many organizations add connectors for GitHub, Figma, Zendesk, and Salesforce during onboarding and never audit them again. Each active connector extends the exfiltration surface in direct proportion to the data the connector can reach.

The access scope also extends to uploaded files and archived content. When a user uploads a document to Rovo for summarization, that file enters the same context window as the rest of the connected data. This is the design property PromptArmor's attack exploits.

The RovoBlast Attack: One-Click Exfiltration via URL Parameter

Varonis Threat Labs disclosed RovoBlast at DEF CON 34 in August 2026. The vulnerability exploited a URL parameter called rovoChatPrompt that Atlassian's interface used to pre-fill text into the Rovo chat window. Varonis named this class of flaw parameter-to-prompt (P2P) injection.

A second design flaw compounded the risk: Atlassian routed requests even when the organization ID segment of the URL was left blank, silently inserting the victim's default organization. An attacker did not need to know the target's organization ID in advance. Any authenticated Rovo user was reachable with a single generic URL.

The attack chain was five steps:

  • An attacker crafts a URL with a malicious instruction in the rovoChatPrompt parameter.
  • A victim clicks the link. One click, no additional authorization prompt.
  • The malicious text populates Rovo's chat window as if the user typed it directly.
  • Rovo's ResearchAgent executes the instruction across all connected data sources.
  • Sensitive content is retrieved and sent to an attacker-controlled endpoint.
  • Varonis published three proof-of-concept demonstrations showing exfiltration of Confluence pages, Jira tickets, and SharePoint content containing personal data. The attack required no jailbreak, no permission bypass, and no technical knowledge on the part of the victim.

    Atlassian deployed a server-side fix on July 8, 2026. If your Rovo environment was active between May and early July, review audit logs for any user who may have clicked an unexpected or untrusted link during that window. Given that no CVE was published and no mass notification was sent, many teams have not conducted this review.

    The PromptArmor Attack: Zero-Click via Document Upload

    PromptArmor disclosed a second, structurally different vulnerability on August 5, 2026. The disclosure timeline began on May 23, 2026. Atlassian acknowledged receipt on May 25 and opened a case. After follow-up attempts on June 4 and July 29, PromptArmor reported no substantive response. The vulnerability remained open at publication.

    This attack uses indirect prompt injection: malicious instructions embedded inside a document rather than a URL parameter. The victim does not need to click anything unusual. The act of uploading a document and asking Rovo a normal question is sufficient.

    The attack chain:

  • An attacker creates a document containing hidden instructions alongside legitimate-looking content.
  • A legitimate user uploads or references that document and asks Rovo a routine question, for example "summarize my open Jira tickets for this sprint."
  • Rovo processes the user's query alongside the document in a shared context window.
  • The injected instructions override Rovo's intended behavior. Rovo searches Jira and Confluence as directed and constructs a URL containing the retrieved data.
  • Rovo's URL retrieval tool fetches the attacker-constructed URL, sending the data to the attacker's server.
  • The user receives a normal-looking response. No alert fires.
  • PromptArmor identified the root cause as a lack of validation on Rovo's URL retrieval tool: there are no protections against opening a URL that has been dynamically constructed by the agent during a session. The retrieval tool executes any URL the agent produces, regardless of whether that URL was injected through adversarial content.

    The web-search control bypass deserves specific attention. Many organizations disabled Rovo's web search feature believing it would prevent the agent from contacting external URLs. PromptArmor confirmed this setting does not remove the URL retrieval capability. The web search toggle and the retrieval tool are separate system components, and the admin console only exposes one of them. Disabling web search does not close this exfiltration path.

    You can read the full PromptArmor technical disclosure at promptarmor.com/resources/atlassian-rovo-exfiltrates-data.

    The Permanent Attack Surface Problem

    Rovo cannot be fully uninstalled. It is included with Atlassian's Premium and Enterprise cloud plans as a bundled capability. Administrators can restrict which users access Rovo through Rovo Access controls and can disable connectors and configure blocklists, but the AI layer itself remains present in the environment.

    This creates a governance situation unlike optional third-party SaaS integrations. Every future prompt injection vulnerability disclosed in Rovo is a vulnerability your organization carries for as long as you run Premium or Enterprise. The Atlassian community thread "Why Can't You Disable Rovo? And What to Do Instead" reflects the genuine frustration this constraint has created among enterprise security teams.

    The practical implication is that configuration, monitoring, and connector scoping replace removal as your risk controls. There is no remediation path that involves uninstalling the product. BeyondScale's assessment work across enterprise Atlassian environments consistently finds that connector scope is the highest-impact control and the one most commonly left at defaults.

    CISO Hardening Checklist

    These controls are ordered by impact. Act on the top items first.

    Connector scope

    Audit every enabled connector and remove any that are not in active, documented use. The default set at many organizations includes connectors enabled during onboarding and never reviewed. For remaining connectors, configure data-source blocklists: Atlassian's admin console supports granular blocklists for Google Drive, SharePoint, and other connectors to exclude specific drives, sites, content types, or sensitive folders.

    Do not connect Rovo to systems containing regulated data (HIPAA-covered clinical notes, PCI-scoped workflow data, ITAR-controlled documentation) without first verifying DLP coverage on the connector output, data residency alignment, and audit log instrumentation for that specific connector. The Outlook connector warrants a separate review: it requests delegated permissions that include calendar read, extending Rovo's access beyond documents into meeting metadata and scheduling data.

    Access restriction

    Use Rovo Access to restrict the feature to user groups with a documented business need. Not every Atlassian user needs Rovo enabled. Apply space-level restrictions in Confluence: Rovo respects Confluence space permissions, so moving sensitive spaces (security runbooks, incident postmortems, personnel data, legal hold content) to restricted access limits retrieval scope even if an injection occurs. This is your most effective blast radius control inside the current attack surface.

    Disable document-based Rovo agent workflows (asking Rovo to analyze or summarize uploaded files) until the PromptArmor indirect injection disclosure is patched. The document summarization workflow is the exact pattern the open vulnerability targets.

    Audit and monitoring

    Enable Atlassian Guard Premium for user-level Rovo audit coverage. The standard audit log captures admin actions. Guard Premium extends coverage to user-level Rovo interactions including chat initiation, agent executions, connector queries, and file uploads to Rovo sessions.

    Export Rovo audit events to your SIEM and write detection rules for: high-volume queries from a single session, queries that retrieve from three or more connectors in sequence, agent sessions that initiate outbound URL fetches, and any Rovo session that accesses spaces or connectors outside the user's normal work pattern. For CASB integration, instrument Rovo connector activity with volume thresholds to flag bulk data retrieval from any single connector in a short window.

    Data residency and encryption

    Configure Rovo's data residency to match your Confluence and Jira region settings. Mismatched residency sends AI-processed content to a different region than the source data, which may create compliance gaps under GDPR Article 46 or applicable data localization requirements.

    Review Atlassian's third-party LLM sub-processors. Atlassian routes Rovo queries through OpenAI, Anthropic, and Google depending on task type. Verify these sub-processors appear in your vendor risk inventory and that their data processing agreements align with your regulatory obligations. Customer-Managed Keys (CMK) are available for Atlassian Enterprise and provide additional control over at-rest encryption, though they do not address in-session exfiltration risk.

    Incident response

    Build a Rovo-specific scenario into your AI incident response playbook. The exfiltration path in both disclosed attacks, where the agent fetches an attacker-constructed URL containing victim data, is structurally different from standard DLP events and will not trigger most existing SIEM rules without purpose-built detection. For the RovoBlast window specifically (before July 8, 2026 patch), run a retroactive audit log review for users who may have clicked untrusted links while Rovo was active.

    When to Restrict Rovo to Search-Only or Block It Entirely

    Some environments cannot absorb the current risk posture. Consider restricting Rovo to passive search (no agents, no ResearchAgent capability) or blocking the feature entirely if any of the following apply:

    • Your Atlassian environment contains systems of record for regulated data with no verified DLP coverage on Rovo connector output.
    • You have not enabled Guard Premium and cannot instrument user-level Rovo activity in your SIEM.
    • Users routinely receive and process documents from external parties and use Rovo to summarize them. This is the exact workflow the PromptArmor zero-click attack targets.
    • The PromptArmor indirect injection disclosure is still open when you conduct your risk assessment. Check Atlassian's security advisories page and the PromptArmor disclosure for current patch status before enabling document-based Rovo workflows.
    Restricting to search-only removes agent execution capabilities including the ResearchAgent's URL retrieval, while preserving cross-system search value for most users. It is a meaningful risk reduction without eliminating the product's primary value proposition.

    The Broader Pattern: Enterprise AI Assistants and Blast Radius

    Rovo illustrates a structural pattern across enterprise AI assistants. Microsoft 365 Copilot, Salesforce Agentforce, ServiceNow AI, and Rovo follow the same architecture: read access across organizational data, a context window that combines trusted system prompts with untrusted external content, and an agent layer that can take outbound actions. Each of these products has seen prompt injection disclosures, and the blast radius in each case is proportional to connector scope.

    NIST's AI Risk Management Framework 1.0 identifies system prompt isolation and output monitoring as foundational controls for AI systems with access to enterprise data. The hardening principles for Rovo map directly to NIST AI RMF's Govern and Manage functions: minimize the attack surface, monitor for anomalous behavior, and maintain documented controls that you can verify during an audit.

    The practical starting point is a scan of your current AI attack surface, which is what our AI security scanner is built for. For organizations managing multiple enterprise AI deployments across Atlassian, Microsoft, Google, and Salesforce, our AI security audit guide for SMBs covers the full program structure with a focus on what security teams can execute without a dedicated AI security budget.

    The July 2026 RovoBlast patch reduced immediate risk. The open PromptArmor disclosure means the document upload exfiltration path is still live at this writing. Scope your connectors, restrict document agent workflows, enable Guard Premium, and instrument Rovo activity in your SIEM. These four actions cover the highest-impact controls without waiting for Atlassian's patch.

    Check your AI endpoint against these findings

    SecureTom runs a free quick scan on any AI endpoint in about a minute. No signup needed.

    Run a free scan
    BT

    BeyondScale Team

    AI Security Team

    The SecureTom research team at BeyondScale Technologies, an ISO 27001 certified company. We build the scanner and publish what we learn testing production AI systems.