Atlassian fixed Rovo AI link-injection flaw that could steal Confluence, Jira, Bitbucket, and SharePoint data

Atlassian patched a critical flaw in its Rovo enterprise AI assistant that could let a single malicious link plant attacker instructions into a user’s live AI session and exfiltrate company data. Varonis calls the technique 'RovoBlast' and says it abused the rovoChatPrompt URL parameter and default organization routing, with no CVE listed in this report. The issue affected Rovo’s access to Atlassian apps and connected services including Microsoft 365, Google Workspace, Slack, and SharePoint, and could trigger autonomous multi-step data retrieval through Rovo’s ResearchAgent.
Why it matters: Organizations using Rovo could have had sensitive internal documents and tickets pulled out through a one-click phishing-style link, so administrators should review Rovo integrations, restrict access to sensitive systems, and monitor AI assistant activity. The flaw is already fixed, but the story matters because it shows how connected AI assistants can turn one user action into broad enterprise data exposure.

Sources

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
Eduard Kovacs 2026.08.08 100% relevant
This article is the initial disclosure of the RovoBlast vulnerability and Atlassian's fix, establishing a distinct enterprise AI data-exposure event not listed among existing tracked stories.
← Back to all stories