RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian addressed the reported URL-based issue on the server side after responsible disclosure, with the fix deployed on July 8, 2026. Rovo is Atlassian’s enterprise AI assistant, designed to search, summarize, and take actions across Jira, Confluence, Bitbucket, and third-party SaaS platforms. Its value comes from access to organizational context. However, the same broad access can create a major security risk when attacker-controlled content is treated as trusted instructions. The RovoBlast attack abused a URL parameter...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!