Attackers' commands enable Rovo, Atlassian’s Jira and Confluence assistant, to gather data accessible to authenticated users This article explores malicious instructions rovo. . One route remains unverified.

The document claimed that uploading a file would allow the assistant to collect internal information and transmit it via a URL request without requiring additional authorization steps. They discovered that the rovoChatPrompt URL parameter could pre-load malicious instructions into Rovo Chat, allowing an authenticated user's actions to be executed with elevated privileges and transmitting results back to an attacker-controlled server via a single click. PromptArmor reported disclosing the issue to Atlassian on May 23, 2026, received a case number two days later, followed up on June 4 and again on July 29, and finally published after no further communication was received.

The report is rated P2 on Bugcrowd’s priority scale and offered a $6,000 bounty; Atlassian implemented the necessary server-side fix as of July 8th, and the issue has been marked resolved. This distinction should guide how risks are assessed rather than diminish them: in an assistant integrated across Atlassian products and linked third-party applications, the extent of a single account's functionality mirrors its intended capabilities. To address the separate content-borne risk, organizations should review which apps and groups have Rovo access, tighten underlying permissions and connector scopes, and avoid treating the web-search toggle as a complete security boundary.