news.mlab.sh
Back to the feed
vulnerability

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

High
Image: The Hacker News
Summary

Atlassian’s Rovo assistant has two vulnerabilities that could allow attackers to exfiltrate data. The first, a one-click link flaw, has been patched by Atlassian. The second, a content-borne prompt injection attack, allows attackers to trick Rovo into sending data to external servers, though this vulnerability remains unresolved as of August 8, 2026. While the immediate risk is contained due to the fix, organizations need to review Rovo access permissions and connector scopes to mitigate the ongoing content-borne risk.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.