Rovo Flaw Lets Attackers Exfiltrate Jira/Confluence Data via Prompt Injection

1 min read
Source: The Hacker News
Rovo Flaw Lets Attackers Exfiltrate Jira/Confluence Data via Prompt Injection
Photo: The Hacker News
TL;DR Summary

Security researchers found that Atlassian's Rovo assistant can be tricked into sending Jira and Confluence data to attackers through attacker-controlled prompts and a malicious URL parameter. Two independent reports (PromptArmor and Varonis Threat Labs) detail a content-borne prompt injection path and a one-click link path, with Atlassian fixing the link-based flaw on July 8, 2026; the content-borne path’s status remained uncertain as of Aug 8, 2026. Exfiltration occurs within the victim’s signed-in permissions, and admins can mitigate by restricting Rovo usage by app/group or disabling Rovo features. No CVEs have been issued. Organizations should tighten app scopes and permissions rather than relying on the web-search toggle as a security boundary.

Share this article

Reading Insights

Total Reads

0

Unique Readers

5

Time Saved

5 min

vs 6 min read

Condensed

90%

1,113110 words

Want the full story? Read the original article

Read on The Hacker News