Your AI Assistant Could Be Leaking Confidential Data – The Atlassian Rovo Risk You Need to Know

Why an AI assistant data leak matters to your business
If you rely on Atlassian tools such as Jira or Confluence, you probably already use the Rovo AI assistant to speed up ticket triage, draft documentation, or fetch information. If you don’t lock down the assistant now, attackers could walk out of your Jira or Confluence with sensitive customer or financial data. In plain terms: a seemingly helpful chatbot could become a data‑leak pipe if you’re not careful. The good news is that the risk can be limited with a few practical settings and monitoring steps.
The incident in a nutshell
In early August 2026 two independent security researchers reported that Rovo – Atlassian’s AI‑powered assistant – could be fed malicious instructions (known as prompt‑injection) that make it harvest information from Jira or Confluence and then forward that information to an external URL. One research team (PromptArmor) demonstrated the attack by hiding the malicious prompt inside a document that a user uploads. Another team (Varonis Threat Labs) showed that a single crafted link could trigger the same exfiltration with just one click from an authenticated user. Atlassian has patched the link‑based flaw, but the document‑based path remains a configuration issue that each organisation must address.
What is prompt‑injection?
Prompt‑injection is a way of “talking back” to an AI model by slipping hidden commands into the text the model is asked to process. Think of it as a sneaky footnote that tells the assistant, “instead of answering, go fetch these files and send them to this address.” It’s like slipping a hidden note into a form that tells the chatbot to hand over the contents of the file instead of answering the question. The AI, seeing the instruction as part of the user’s request, obeys – because it does not distinguish between genuine user intent and hidden commands.
How the Rovo flaw works
1. File‑based prompt‑injection attack (PromptArmor)
- Upload a malicious file – An attacker places a hidden instruction inside a document (for example, a PDF or Word file).
- Ask Rovo to process the file – A legitimate user asks Rovo to “organise my Jira tickets” and attaches the file.
- Rovo reads the hidden prompt – The model treats the concealed text as a command and proceeds to gather any Jira or Confluence data the user can see.
- Data is sent out – Rovo appends the gathered information to an attacker‑controlled URL and makes an outbound request, delivering the data without any extra approval step.
Even a regular employee who can upload a document can trigger the leak if the assistant is allowed to read that file.
2. Link‑based injection (Varonis Threat Labs – “RovoBlast”)
- Craft a special URL – The attacker creates a link that includes the
rovoChatPromptparameter, which pre‑loads a full prompt into Rovo’s chat window. - User clicks the link – An authenticated user, already signed into Atlassian, clicks the link.
- Rovo executes the prompt – With the user’s privileges, Rovo fetches internal data and sends it to the attacker’s server in a single request.
The link‑based attack has been patched on Atlassian’s side (July 8 2026). The file‑based path is not a code flaw but a configuration gap: Rovo is allowed to read any uploaded content and to make outbound HTTP requests without a separate safety check.
What you can do right now
Even if you are not an IT specialist, you can apply these steps to reduce the risk:
- Limit who can use Rovo – Restrict the assistant to a small group of administrators or power users. In Atlassian’s admin console, assign Rovo permissions only to trusted roles.
- Disable web‑search for Rovo – Turn off the organisation‑wide “Rovo web‑search” toggle. In the Atlassian admin console, go to Settings → AI assistants → Rovo and toggle ‘Web‑search’ off.
- Turn off markdown image rendering – Rovo can render images from URLs that appear in its output. Disabling this feature prevents a hidden image URL from acting as a data‑exfiltration channel.
- Control file uploads – Enforce strict file‑type policies and scan uploaded documents for hidden scripts or suspicious content before they reach Rovo.
- Monitor outbound traffic – Set up alerts for unexpected HTTP requests from your Atlassian servers, especially to unknown domains. Many cloud‑security tools can flag such anomalies.
- Apply least‑privilege principles – Ensure that users who interact with Rovo only have access to the data they truly need. If a user cannot see a confidential Jira project, Rovo cannot leak it either.
These measures are relatively quick to implement and do not require a full system overhaul.
Frequently asked questions
Q: Do I need to stop using Rovo altogether?
A: Not necessarily. Rovo can still be a productivity boost if you lock it down to trusted users, disable risky features, and keep an eye on outbound traffic.
Q: Will turning off web‑search affect Rovo’s usefulness?
A: It will limit Rovo’s ability to pull information from public websites, but the core functions—searching within your own Jira and Confluence data—remain intact.
Q: What signs show that my Rovo assistant might be mis‑used?
A: Look for unusual outbound requests in your network logs, especially to domains you do not recognise. Review recent Rovo chat histories for unexpected URLs or image links, and set up alerts for spikes in data‑export activity.
Protect against AI assistant data leaks – free review with IT Move NL
Understanding the risk is the first half of the battle; securing your environment is the second. Our Security & Protection service offers a free 30‑minute security review of your Atlassian environment – book with IT Move NL today. We’ll audit Rovo permissions, verify that risky features are disabled, and help you put in place continuous monitoring for any data‑exfiltration attempts.
Don’t let an AI assistant become a hidden doorway for attackers. Contact us today and keep your business data where it belongs – under your control.
Sources:

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent
Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.
STAY IN THE LOOP
// Cloud, AI & DevOps insights — straight to your inbox.
No spam. Unsubscribe anytime.
// Related articles
Need help with your cloud infrastructure?
Our team of experts is ready to help you navigate the complexities of modern cloud architecture.
Get in Touch

