Critical Vulnerability in Azure Cosmos DB Exposed Databases Globally

Critical Vulnerability in Azure Cosmos DB Exposed Databases Globally

First seen 30 Jul 2026, 16:09 UTC News.YcombinatorFeeds.4Sysopswww.vicarius.io 86% similarity 69.0

Article Content

Browse articles
ThreatCluster

Wiz Research identified a critical vulnerability named CosmosEscape in Azure Cosmos DB via its Gremlin API. This flaw allowed attackers to access every database within the service, including Microsoft's internal databases, by exploiting the Cosmos Master Key. The attack method involved retrieving primary keys for full read and write access and enumerating databases using organization identifiers. Microsoft has confirmed that the vulnerability has been fully remediated by eliminating the Cosmos Master Key and implementing new security measures. An investigation revealed no evidence of exploitation beyond the research conducted. Cosmos DB is widely used across Microsoft services, raising concerns about potential data exposure. The vulnerability highlights risks associated with custom query engines in cloud services.

Key Points: • CosmosEscape allowed access to all databases in Azure Cosmos DB, including internal Microsoft databases. • The vulnerability was mitigated by removing the Cosmos Master Key and enhancing security protocols. • No evidence of exploitation was found beyond the research conducted by Wiz Research.

ThreatCluster AI How this analysis works

Timeline

2026-07-30
CosmosEscape vulnerability disclosed
Wiz Research revealed a critical vulnerability in Azure Cosmos DB that could compromise all databases.
News.Ycombinator
2026-07-30
Microsoft remediates CosmosEscape
Microsoft announced the removal of the Cosmos Master Key and confirmed no unauthorized access occurred.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story