{"id":17582,"date":"2026-08-10T00:35:46","date_gmt":"2026-08-10T00:35:46","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17582"},"modified":"2026-08-10T00:35:46","modified_gmt":"2026-08-10T00:35:46","slug":"crucial-one-click-on-vulnerability-in-atlassians-rovo-ai-uncovered-enterprise-information","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17582","title":{"rendered":"Crucial One-Click on Vulnerability in Atlassian&#8217;s Rovo AI Uncovered Enterprise Information"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\"><strong>DEF CON \u2014 Varonis Risk Labs has disclosed a one-click vulnerability in Rovo, Atlassian\u2019s enterprise AI assistant, that permit a specifically crafted hyperlink seed attacker-controlled directions straight right into a person\u2019s dwell AI session.\u00a0<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Dubbed <strong>RovoBlast<\/strong>, the flaw required no jailbreak and no permission bypass, counting on the truth that the assistant merely handled externally provided parameters as trusted enter.<\/p>\n<p class=\"wp-block-paragraph\">Rovo capabilities as an AI layer spanning Jira, Confluence, Bitbucket, and third-party instruments equivalent to Slack, Microsoft 365, and Google Workspace. It additionally carries autonomous agent options able to finishing multi-step duties with no additional person involvement, which is what enabled the RovoBlast assault.\u00a0<\/p>\n<p class=\"has-text-align-center wp-block-paragraph\"><strong>[ Read:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones\/\">How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones<\/a> <strong>]<\/strong><\/p>\n<p class=\"wp-block-paragraph\">The exploit leveraged a URL parameter known as <em>rovoChatPrompt<\/em>, which pre-fills content material straight into Rovo\u2019s chat window. Varonis researchers describe this assault path as parameter-to-prompt (P2P) injection, which they beforehand reported in Microsoft Copilot as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/new-reprompt-attack-silently-siphons-microsoft-copilot-data\/\">Reprompt<\/a> in January.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Researchers seen that the group ID a part of the URL could possibly be left clean and Atlassian would nonetheless route the request into the sufferer\u2019s personal default group, all with none warning or indicator that the session had been seeded by an outdoor supply.<\/p>\n<div class=\"zox-post-ad-wrap\"><span class=\"zox-ad-label\">Commercial. Scroll to proceed studying.<\/span><\/div>\n<p class=\"wp-block-paragraph\">To gauge the potential blast radius, the researchers merely requested Rovo what knowledge it might see. The AI\u2019s reply included Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded information, internet pages, and archived content material.<\/p>\n<p class=\"wp-block-paragraph\">The precise leakage got here from ResearchAgent, certainly one of Rovo\u2019s built-in instruments, which may autonomously conduct multi-source internet analysis and navigate throughout arbitrary websites. As soon as an attacker\u2019s immediate was seeded via the malicious hyperlink, that very same functionality let Rovo pull inside knowledge and push it out to the open internet in a single automated chain.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The group demonstrated the approach in three separate proof-of-concept situations: exfiltrating Confluence pages, Jira tickets, and SharePoint content material containing private knowledge.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter is-resized\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.airisksummit.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"264\" src=\"https:\/\/www.securityweek.com\/wp-content\/uploads\/2026\/06\/AI_Risk-970x250-v2-1024x264.jpg\" alt=\"\" class=\"wp-image-47364\" style=\"width:646px;height:auto\" srcset=\"https:\/\/www.securityweek.com\/wp-content\/uploads\/2026\/06\/AI_Risk-970x250-v2-1024x264.jpg 1024w, https:\/\/www.securityweek.com\/wp-content\/uploads\/2026\/06\/AI_Risk-970x250-v2-360x93.jpg 360w, https:\/\/www.securityweek.com\/wp-content\/uploads\/2026\/06\/AI_Risk-970x250-v2-768x198.jpg 768w, https:\/\/www.securityweek.com\/wp-content\/uploads\/2026\/06\/AI_Risk-970x250-v2.jpg 1455w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"\/><\/a><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Notably, the researchers discovered {that a} single seeded hyperlink was typically sufficient to set off the leak. The assault didn\u2019t require chaining a number of requests or any extra bypass steps to get Rovo to retrieve and summarize delicate knowledge. <\/p>\n<p class=\"wp-block-paragraph\">Varonis disclosed RovoBlast to Atlassian, which mounted the difficulty earlier than the findings have been printed.<\/p>\n<p class=\"wp-block-paragraph\">The researchers advocate that organizations restrict which techniques Rovo can attain, disconnect unused integrations, wall off delicate areas equivalent to authorized, HR, and finance, disable looking or multistep automation options that aren\u2019t in lively use, and pair this with routine monitoring of assistant exercise logs.<\/p>\n<p class=\"wp-block-paragraph\">Varonis introduced the analysis at DEF CON 34 on Friday. A technical write-up is on the market on the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.varonis.com\/blog\/rovoblast\">Varonis weblog<\/a>.<\/p>\n<p class=\"has-text-color has-link-color wp-elements-bd5d255893dc352bcdfed61cccb66af2 wp-block-paragraph\" style=\"color:#535353\"><em>*assertion from Atlassian eliminated at Atlassian\u2019s request<\/em><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts\/\">Zero-Click on AI Browser Hacking: Claude and ChatGPT Atlas Hijacked by way of Emails, X Posts<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/meta-ai-hacked-external-systems-during-cybersecurity-testing\/\">Meta AI Hacked Exterior Methods Throughout Cybersecurity Testing<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/atlassian-splunk-patch-critical-vulnerabilities\/\">Atlassian, Splunk Patch Crucial Vulnerabilities<\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>DEF CON \u2014 Varonis Risk Labs has disclosed a one-click vulnerability in Rovo, Atlassian\u2019s enterprise AI assistant, that permit a specifically crafted hyperlink seed attacker-controlled directions straight right into a person\u2019s dwell AI session.\u00a0 Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, counting on the truth that the assistant merely handled externally [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17584,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10104,420,157,3128,1972,10058,10095,1061],"class_list":["post-17582","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-atlassians","tag-critical","tag-data","tag-enterprise","tag-exposed","tag-oneclick","tag-rovo","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17582"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17582\/revisions"}],"predecessor-version":[{"id":17583,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17582\/revisions\/17583"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17584"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-10 02:41:22 UTC -->