A Single Click Could Have Handed Hackers Your Company's Confluence and Jira Files

Researchers found a flaw in Atlassian's Rovo AI assistant that let an attacker steal data from widely used workplace tools with almost no effort from the victim.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
A computer mouse pointer hovering over a link in an email interface, with office collaboration tool icons visible on the background desktop
Share

Key points

  • Varonis researchers discovered an attack method, named RovoBlast, targeting Atlassian's Rovo AI assistant.
  • A single click by an unsuspecting employee was enough to trigger the attack.
  • Data stored in Confluence, Jira and SharePoint was all within reach.
  • Atlassian has since fixed the vulnerability.
  • SecurityWeek first reported the flaw.

What happened?

Researchers at Varonis, a data-security company, uncovered a way to weaponise Atlassian's Rovo AI assistant, a tool built into popular workplace software that helps staff search and summarise company information. RovoBlast could let a criminal steal documents stored in Confluence (a team wiki tool) and Jira (a project-tracking tool), as well as files held in Microsoft SharePoint, all without a password. The victim's part was a single click.

We first reported on Rovo's exposure to hidden-instruction attacks on 8 August, when two research teams showed the same class of flaw; only one of those tricks had been fully closed at that point.

How did it work?

The flaw was a prompt injection: hidden malicious instructions buried inside content that the AI assistant would later read and act on. When an employee opened a booby-trapped page or document, Rovo AI silently read those instructions and carried them out, pulling sensitive files and forwarding them to the attacker.

No skill required from the victim's side. Open the wrong document, lose the data.

Who is at risk?

Any organisation running Rovo AI alongside Confluence, Jira or SharePoint was potentially exposed. Atlassian's products are used by hundreds of thousands of teams worldwide, and the data in those tools frequently includes source code and financial records. Atlassian has patched the flaw, so teams that keep their software current aren't vulnerable to this specific attack.

Should employees do anything?

Confirm with your IT team that Rovo AI is running the latest version. Beyond that, the practical lesson here is simple: be cautious about opening documents shared by people you don't know, even inside internal tools that feel safe. That's where trust gets exploited.

Item Detail
Attack name RovoBlast
Discovered by Varonis researchers
Products affected Confluence, Jira, SharePoint (via Rovo AI)
Trigger required One click by the victim
Patch status Fixed by Atlassian

The real story here isn't the patch. It's that AI assistants wired into sensitive business data inherit all the trust employees place in those systems, and attackers now know it. Rovo won't be the last assistant to become the attack surface.

© 2026 Threat Vectr