The Hacker News reported that two security firms independently found ways to make Atlassian Rovo collect data accessible to a signed-in user and send it to an attacker-controlled server.
PromptArmor demonstrated an indirect prompt-injection chain in which malicious instructions hidden in content could cause Rovo to search Jira and Confluence and append retrieved data to an attacker-controlled URL.
Varonis Threat Labs found a separate RovoBlast issue in which the rovoChatPrompt URL parameter could preload attacker instructions into Rovo Chat.
The RovoBlast path required one click from an authenticated user and could cause Rovo to run instructions with that user’s privileges.
Varonis reported the issue through Bugcrowd, and the Bugcrowd record shows Atlassian fixed that server-side issue on July 8, 2026.
The reported techniques did not demonstrate a tenant-wide authorization bypass; the data at risk was constrained by what the victim account could already access.
The Hacker News reported that the status of the separate PromptArmor content-borne path after its August 5, 2026 publication remained unconfirmed.
Research into Atlassian Rovo shows how attackers can exploit a user’s legitimate access privileges to exfiltrate data through enterprise AI assistants by introducing attacker-controlled instructions via crafted links or malicious content. The reported techniques caused Rovo to retrieve information available to the authenticated user from systems such as Jira and Confluence and transmit that data to attacker-controlled destinations.
How Prompt Injection Turned Rovo’s User Access Into a Data-Exfiltration Path
The RovoBlast technique abused the rovoChatPrompt URL parameter to preload attacker-controlled instructions into Rovo Chat. When an authenticated user followed a crafted link, those instructions could execute within the context of the user’s existing Rovo session and permissions.
PromptArmor described a separate indirect prompt-injection path. In that attack chain, malicious instructions embedded in content processed by Rovo could direct the assistant to search Jira and Confluence, incorporate information it retrieved into an attacker-controlled URL, and embed that URL in the rendered output using an image tag or Markdown image syntax such as ![](). Rendering the response could then cause the client to automatically fetch the attacker-controlled URL, transmitting the encoded information without requiring the user to click the link or separately approve the outbound data transfer.
The distinction matters. Neither technique required the attacker to independently obtain the victim’s Jira or Confluence permissions. Instead, the attack could exploit the access already available to the authenticated user, making legitimate authorization part of the exfiltration path.
This exposes a broader architectural risk with enterprise AI agents: when the same agent can consume untrusted instructions, access sensitive internal data, and produce rendered content capable of automatically initiating outbound requests, prompt injection can potentially connect those capabilities into a data-exfiltration chain. Indirect prompt injection is a recognized risk for LLM applications that process external or attacker-influenced content.
What is DEX Management? (And Why You Need It)
DEX Management helps IT spot digital friction early, resolve issues faster, and boost productivity.
Reducing the Exposure with Hexnode UEM
Hexnode UEM can help reduce the identity and endpoint risk surrounding AI-enabled SaaS access by ensuring that access originates from managed devices that meet defined security requirements. Administrators can establish compliance criteria around factors such as device encryption, password policies, required or blocklisted applications, device activity, and jailbreak/root status.
For organizations using Microsoft Entra Conditional Access, Hexnode can operate as a third-party device compliance partner and report device compliance status to Entra ID. Conditional Access policies can then require a device to be marked compliant before granting access to protected organizational resources.
Hexnode does not sanitize malicious prompts or prevent prompt injection within an AI assistant itself. Its role is to enforce a Zero Trust access-control boundary around the identities, devices, and SaaS resources involved. Even if a user encounters or clicks a malicious link designed to exploit an AI-enabled workflow, appropriately configured Conditional Access policies can prevent unauthorized, unmanaged, or non-compliant endpoints from establishing permitted sessions or accessing protected resources such as Jira and Confluence.
This distinction is important because prompt injection can attempt to exploit the permissions available within an authenticated session. By restricting access to trusted, compliant endpoints and continuously enforcing device-security requirements, Hexnode can reduce the surrounding attack surface and help ensure that access to sensitive SaaS data remains subject to organizational security policy, even though the prompt-injection vulnerability itself must be addressed within the AI application and its security controls.
RovoBlast and related prompt-injection research reinforce a broader security principle: enterprise AI agents need explicit boundaries around both data access and external actions. When an assistant operates with a user’s legitimate permissions, prompt injection can potentially turn authorized access into an unintended data-exfiltration path.
Enterprises should apply least-privilege access to AI connectors, constrain unnecessary external actions, and monitor AI-assisted activity for anomalous behavior. For sensitive workflows, organizations should also incorporate identity controls and managed-device compliance into access decisions, reducing the privileges and resources exposed when an AI interaction is compromised.
Try Hexnode free for 14 days
Secure enterprise access with Hexnode. Sign up today to strengthen your endpoint security posture.
I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.