Utopia Tech
SecurityAI-assisted1 min read

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Security researchers have discovered vulnerabilities in Atlassian's Rovo AI assistant that allow attackers to extract sensitive Jira and Confluence data accessible to authenticated users by injecting malicious instructions. Two security firms independently identified different attack vectors, with only one confirmed as patched. The exploit involves embedding attacker-controlled prompts in content

UT

Utopia Tech

August 8, 2026 · 1 min read

Share

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content