AI assistants are becoming increasingly integrated into the tools businesses use every day. Atlassian Rovo can search, summarize, and work with information across Jira, Confluence, and connected applications, bringing significant opportunities for productivity.
But greater AI capabilities also introduce new security considerations. Recent research has highlighted the importance of building AI systems that are governed as carefully as the business systems they interact with.
Understanding the Recent Research
In mid-2026, security researchers uncovered two different prompt-injection techniques targeting Rovo.
RovoBlast: This vulnerability used a specially crafted link to trick Rovo into processing attacker-supplied instructions within a user's authenticated session.
Indirect Prompt Injection: A separate research team demonstrated that malicious instructions embedded in content, such as a Jira ticket or Confluence page, could influence Rovo's behavior.
These findings highlight a broader challenge for AI systems: they must distinguish between instructions they should follow and information they should simply process.
How Atlassian Strengthened Rovo Security
Atlassian responded to the two findings with different measures. The RovoBlast vulnerability was addressed with a server-side fix deployed on July 8, 2026. For the separate indirect prompt-injection attack, Atlassian introduced additional security hardening focused specifically on limiting how Rovo can interact with content and external destinations controlled by untrusted sources.
These product-level changes also introduced new controls that organizations can use to further manage Rovo's access and reduce their own exposure to AI-related risks.
1. Restricting External URL Access
One important change addresses how Rovo handles URLs and content originating from untrusted sources.
Atlassian has limited URL reader tool calls and Markdown rendering to trusted sources, including user inputs, Atlassian applications, and Rovo Connectors.
This means that instructions embedded in untrusted content can no longer simply cause Rovo to make HTTP requests to arbitrary external URLs. The change is specifically designed to prevent indirect prompts from using Rovo's capabilities to communicate with attacker-controlled external destinations.
Rovo can still work with URLs handled by supported, authenticated product-specific content readers, including supported Confluence, Jira, Slack, Trello, and Bitbucket content.
At the same time, Rovo's access to live external web content is restricted. It cannot use external web pages as live content sources, render external images through browser-side links, or perform Web Search when these restrictions are applied.
2. Introducing an Organization-Level Web Access Control
Atlassian has also introduced a Web Access setting in Admin Hub.
Administrators can use this organization-level control to determine whether Rovo can access web-available data sources. This gives organizations another way to manage their AI attack surface according to their own security requirements.
For organizations that do not need Rovo to access external web content, keeping Web Access disabled can provide an additional layer of protection.
3. Building a Multilayered Defense
Atlassian's response is not based on a single filter or feature. The company describes indirect prompt injection as an inherent risk for prompt-based AI systems and is continuing to add layers to its security defenses.
This is an important distinction. Prompt injection cannot simply be treated like a conventional vulnerability with one permanent patch. An AI assistant can encounter new types of content and instructions as its capabilities and integrations expand.
The goal is therefore to reduce both the likelihood of successful manipulation and the potential impact if an attack is attempted.
What Should Organizations Do?
Security is a shared responsibility. In addition to Atlassian's product-level protections, organizations should review how Rovo is configured and what types of content it processes.
Audit permissions: Start with the underlying permissions in Jira, Confluence, and connected applications.
Apply least privilege: Limit Rovo access to the users, teams, applications, and data sources that actually require it.
Review Web Access: Consider whether Rovo needs access to web-available data sources. Organizations with no business need for this functionality can keep Web Access disabled.
Treat external content as untrusted: Content submitted by external or unauthenticated users can contain instructions designed to influence an AI system. It should be reviewed before being automatically processed by Rovo agents or automations.
Secure public service portals: For publicly accessible Jira Service Management portals, consider requiring authentication where possible, separating public-facing projects from internal projects, and reviewing whether attachments are necessary.
Govern AI agents: Carefully consider which users can create agents and what applications and tools those agents can interact with.
Keep humans in the loop: Where an AI agent can make consequential changes to business data, human approval can provide an additional layer of control.
The Path Forward
The recent Rovo research is a reminder that AI security requires a layered approach.
Atlassian has responded by strengthening Rovo's handling of untrusted content, restricting potentially risky external URL interactions, introducing organization-level Web Access controls, and continuing to develop additional security measures.
At the same time, indirect prompt injection remains an evolving class of AI security risk. No single control can eliminate it completely.
For enterprises, the practical takeaway is clear: adopting AI assistants should go hand in hand with careful permissions, access controls, data governance, and ongoing security review.
As AI becomes a core part of the enterprise technology stack, secure AI adoption is becoming part of effective IT governance itself.
Need to know more about security and risk management?
Our Atlassian experts can guide you through the important steps towards more secure digital workflows and better risk management.
