A Single Click Could Have Handed Hackers Your Company's Confluence and Jira Files

Researchers found a flaw in Atlassian's Rovo AI assistant that let an attacker steal data from widely used workplace tools with almost no effort from the victim.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Varonis researchers discovered an attack method, named RovoBlast, targeting Atlassian's Rovo AI assistant.
  • A single click by an unsuspecting employee was enough to trigger the attack.
  • Data stored in Confluence, Jira, and SharePoint was all within reach.
  • Atlassian has since fixed the vulnerability.
  • SecurityWeek first reported the flaw.

What happened?

Researchers at Varonis, a data-security company, uncovered a way to weaponise Atlassian's Rovo AI assistant, a tool built into popular workplace software that helps staff search and summarise company information. The attack method they named RovoBlast could let a criminal steal documents and records stored in Confluence (a team wiki tool), Jira (a project-tracking tool), and SharePoint (Microsoft's file-sharing service), all without needing a password.

The catch for the attacker was almost laughably small: they needed the victim to click once.

How did it work?

The flaw was a type of vulnerability called a prompt injection, where a criminal hides malicious instructions inside content that an AI assistant will later read and act on. When an employee opened a booby-trapped page or document, Rovo AI would silently read those hidden instructions and carry them out, including pulling sensitive files and sending them somewhere the attacker controlled.

No technical skill was required from the victim's side. Open the wrong document, lose the data.

Who is at risk?

Any organisation using Atlassian's Rovo AI product alongside Confluence, Jira, or SharePoint was potentially exposed. That covers a wide slice of corporate and government workplaces. Atlassian products are used by hundreds of thousands of teams worldwide, and the data sitting in those tools frequently includes source code, financial records, HR files, and internal strategy documents.

Atlassian has patched the flaw, meaning the fix is already available. Organisations that keep their software up to date are no longer vulnerable to this specific attack.

Should employees do anything?

If your workplace uses Atlassian tools, the most important step is confirming with your IT team that Rovo AI is running the latest version. Beyond that, the broader lesson here is practical: be cautious about opening documents or pages shared by people you do not know, even inside internal tools that feel safe. Attackers increasingly target the content employees trust most.

Item Detail
Attack name RovoBlast
Discovered by Varonis researchers
Products affected Confluence, Jira, SharePoint (via Rovo AI)
Trigger required One click by the victim
Patch status Fixed by Atlassian

The vulnerability is a reminder that AI assistants wired into sensitive business data create new ways for criminals to reach that data. The AI itself becomes the attack surface.

© 2026 Threat Vectr