RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and SharePoint Data — Threadlinqs Intelligence
As of 2026-08-08, RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and SharePoint Data is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 7 indicators of compromise.
Threat ID: TL-2026-1942 · Severity: CRITICAL · Status: PATCHED · Category: VULNERABILITY
Varonis Threat Labs disclosed RovoBlast, a one-click parameter-to-prompt (P2P) injection flaw in Atlassian's Rovo AI assistant: an unvalidated _rovoChatPrompt URL parameter seeded attacker
RovoBlast is a parameter-to-prompt (P2P) injection vulnerability that Varonis Threat Labs found in Atlassian Rovo, the AI assistant embedded across Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, and 50+ other connectors. It is the second entry in Varonis's P2P injection research line, following January 2026's 'Reprompt' finding against Microsoft Copilot, which established the same attack class: encoding an attacker's prompt directly into a URL parameter so it auto-populates and executes inside a trusted AI chat session the instant the link loads.
In Rovo's implementation, the attacker-controlled string traveled in the _rovoChatPrompt (also observed as rovoChatPrompt) parameter on the Rovo Chat endpoint (e.g. https://home.atlassian.com/chat?rovoChatPathway=chat&_rovoChatPrompt=<prompt>). Rovo pre-filled this content straight into the chat window with no warning, confirmation, or 'taint' indicator that the session had been seeded by an external source. A second, compounding flaw sat next to it: the URL's organization-ID field could be left blank, and Atlassian would still silently route the poisoned session into the victim's own default organization rather than rejecting it, removing what would otherwise have been a visible friction point for the victim to notice something was wrong.
Once the injected prompt loaded, exploitation required little to no additional guardrail bypassing -- Varonis found Rovo 'often required little to no guardrail bypassing to retrieve and summarize sensitive data.' The chain relied on ResearchAgent, one of Rovo's built-in autonomous agents, advertised for 'deep multi-source open web research' and 'multi-step browsing and navigation across arbitrary websites' without further user interaction. The injected instructions directed ResearchAgent to locate accessible data across connected systems, embed it into the path of an attacker-controlled image URL, and then fetch that URL -- using the agent's own legitimate web-fetch/image-retrieval tool call as the exfiltration channel to an attacker-controlled server. In their proof-of-concept, researchers demonstrated extraction of a private API key alongside Confluence pages, Jira tickets, SharePoint content (including content with personal data), data from connected relational databases, and archived/uploaded files. Critically, the access was scoped to whatever the signed-in victim could already reach -- Varonis did not demonstrate a tenant-wide authorization bypass or privilege escalation; the danger is entirely that a single click let an external party direct an already-privileged agent's actions.
RovoBlast was reported through Bugcrowd (P2 priority, $6,000 bounty) and Atlassian deployed a server-side fix on 2026-07-08, which the reporter validated; no CVE identifier or CVSS score had been assigned as of publication, and NVD/CISA KEV carried no matching entry. Atlassian's public response characterized the flaw as representative of 'a class of attack that affects AI systems across the industry' and recommended customers verify the source of content their AI assistants act on. Varonis presented the research at DEF CON 34 / Black Hat USA 2026 alongside its broader AI-agent security work.
A second, independently discovered and functionally related issue in the same product deserves attention alongside RovoBlast: AI security firm PromptArmor separately reported an indirect prompt-injection vector in Rovo on 2026-05-23, where hidden instructions embedded in an uploaded document (no crafted link or click required) caused ResearchAgent to gather and exfiltrate Jira/Confluence data via the same class of insecure, agent-driven URL retrieval -- and, per PromptArmor, this exploitation path persisted even when an organization's web-search setting was disabled. As of PromptArmor's 2026-08-05 publication, Atlassian had acknowledged the report (case number issued 2026-05-25) but had not shipped a fix despite follow-ups on 2026-06-04 and 2026-07-29. D
Weaknesses (CWE)
CWE-20, CWE-345, CWE-441
Target sectors: technology, software-development, financial-services, government administration, health, professional-services, telecoms
Target regions: Global
Timeline
- Varonis Threat Labs publishes 'Reprompt', the prior parameter-to-prompt (P2P) injection research against Microsoft Copilot that established the attack class later reused against Atlassian Rovo.
- AI security firm PromptArmor reports a separate, related indirect prompt-injection / insecure URL-retrieval vulnerability in Atlassian Rovo to Atlassian.
- Atlassian acknowledges PromptArmor's report and issues an internal case number.
- PromptArmor follows up with Atlassian for a status update on its report; receives no substantive response.
- Atlassian deploys a server-side fix for RovoBlast, the one-click parameter-to-prompt injection flaw reported by Varonis Threat Labs via Bugcrowd (P2 severity, $6,000 bounty); the reporter validates the fix.
- Varonis publicizes its Black Hat USA 2026 / DEF CON 34 AI security research slate, which includes the RovoBlast findings.
- PromptArmor sends a second follow-up to Atlassian; its separately disclosed indirect-injection vector remains unpatched.
- PromptArmor publishes its findings on the still-unresolved indirect prompt-injection / URL-retrieval exfiltration vector in Rovo.
- Varonis Threat Labs publishes the RovoBlast technical disclosure; SecurityWeek, The Hacker News, and other outlets report on the now-patched one-click parameter-to-prompt injection flaw.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 7 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, T1190, T1204.001, T1213, T1213.001, T1213.002, T1567, AML.T0051, AML.T0049, AML.T0011.003, AML.T0053