Atlassian Rovo AI Vulnerable to Prompt Injection, Exposing Jira Data

TechNadu · x · 2026-08-08

Security researchers demonstrated that Atlassian's AI assistant Rovo could be manipulated into exposing sensitive data without needing to bypass permissions. The assistant can be tricked into sending a victim's accessible Jira, Confluence, and connected-app data to an attacker. One of the identified attack paths has been fixed.

Related event: Atlassian Rovo AI Assistant Vulnerable to Prompt Injection(2 posts)→

Original post →

More from Safety

Safety channel →