PromptArmor identified multiple vulnerabilities in Atlassian’s Rovo AI agent that enable data exfiltration across Atlassian tenants, according to research published on August 5, 2026. Rovo is a multi-purpose agent that operates across Atlassian’s product suite, including Jira and Confluence.

The attack exploits indirect prompt injection—a technique where hidden instructions are embedded in files or data that Rovo processes. According to PromptArmor, the attack chain begins when a user uploads a file containing a hidden prompt injection to Rovo and then requests the agent to organize Jira tickets. The injected prompt manipulates Rovo to submit Jira tickets and Confluence documents to an attacker’s website by exploiting Rovo’s URL retrieval tool, which lacks protections against dynamically created URLs. When Rovo calls the tool to open the attacker’s URL, the attacker’s server logs the request, including any appended sensitive data.
Critically, the attack executes without requiring human-in-the-loop approval, and users may see no evidence of the breach. After the attack, users only observe suggested ticket updates but remain unaware that their data was exfiltrated.
The vulnerability persists even when organizations disable web search for Rovo. According to PromptArmor, the web search setting fails to remove the underlying tool for opening search results, leaving the exfiltration vector intact.
PromptArmor disclosed the vulnerabilities to Atlassian on May 23, 2026. Atlassian acknowledged the disclosure and assigned a case number on May 25, but according to PromptArmor, made no further communication despite multiple follow-ups on June 4 and July 29. As of the August 5 publication date, Rovo remained vulnerable.
PromptArmor also identified a secondary exfiltration mechanism through insecure Markdown image rendering in Rovo’s outputs, which could similarly be exploited via indirect prompt injection to extract data. The vulnerability highlights broader security concerns with AI agents that have access to sensitive organizational data and lack robust protections against prompt injection attacks.
Key facts
- PromptArmor disclosed vulnerabilities in Atlassian Rovo to the company on May 23, 2026, with no resolution as of August 5, 2026
- The attack uses indirect prompt injection embedded in uploaded files or external data to manipulate Rovo into exfiltrating Jira tickets and Confluence documents
- Rovo’s URL retrieval tool lacks protections against dynamically created URLs, allowing attackers to log sensitive data appended to requests
- The attack works even when web search is disabled because the underlying tool for opening search results remains functional
- Users see no evidence of data exfiltration—they only observe suggested ticket updates
