All incidents

RovoBlast vulnerability in Atlassian Rovo AI exposes enterprise data

vulnerabilityopenAug 8, 2026 — Aug 10, 2026
RovoBlast vulnerability in Atlassian Rovo AI exposes enterprise data

RESEARCHERS at Varonis Threat Labs have disclosed a vulnerability dubbed RovoBlast in Atlassian’s Rovo AI assistant that lets an attacker hijack an authenticated user's session through a specially crafted URL and exfiltrate company data to the public web. The flaw affects organisations that rely on Rovo to bridge data from Jira, Confluence, Slack and SharePoint, allowing a single malicious link to leak sensitive information without any further user interaction.

According to Infosecurity Magazine, the vulnerability resides in the rovoChatPrompt parameter, which accepts external input without proper validation, enabling attackers to inject malicious prompts that instruct the AI to retrieve and leak data from connected applications. No CVE identifier has been assigned to the flaw, but Varonis characterised it as critical due to the ease of exploitation and the breadth of data accessible through Rovo.

Because Rovo integrates with platforms such as Jira, Confluence, Slack and SharePoint, a successful attack can pull tickets, documents and messages from those services and send them to an endpoint controlled by the attacker, as highlighted in a report by SecurityWeek. The attack requires only that a logged‑in user clicks a malicious link; no further interaction is needed for the data to be exfiltrated.

Varonis presented the findings at DEF CON 34, prompting Atlassian to release a fix shortly afterwards, although no threat actors have been observed exploiting the vulnerability in the wild to date. Nevertheless, the issue highlights the broader risk posed by AI assistants that ingest external URLs without stringent input sanitisation, especially when they sit atop privileged data stores.

Organisations should verify they are running the patched version of Rovo, review and limit the assistant’s access to only the data stores essential for business operations and disable any unused integrations. Security teams ought to monitor logs for anomalous rovoChatPrompt requests and train users to treat unsolicited links with caution, even when they appear to originate from trusted contacts.

Network controls that block outbound connections to unknown domains can help contain any potential exfiltration, while a strict Content Security Policy adds another layer of defence against malicious input. Finally, regular reviews of access controls and periodic penetration testing of AI‑powered tools will help ensure that similar flaws are identified and remedied before they can be exploited.

Intelligence briefing updated Aug 10, 2026

Root sourcewww.varonis.com
Timeline Coverage

Swipe to explore timeline