Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB to Potential Attacks

Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB to Potential Attacks

First seen 30 Jul 2026, 16:09 UTC News.YcombinatorCybersecuritynewsFeeds.4Sysopswww.vicarius.ioScworld+1 87% similarity 70.5

Article Content

Browse articles
ThreatCluster

Wiz Research disclosed a critical vulnerability named CosmosEscape in Azure Cosmos DB, allowing attackers to potentially compromise every database in the service, including Microsoft's internal systems like Entra ID, Teams, and Copilot. The flaw, residing in the Gremlin API, could have enabled attackers to acquire the Cosmos Master Key, granting full read and write access to databases. This vulnerability posed a significant risk of cross-tenant attacks, potentially impacting millions of workloads. Microsoft has since remediated the issue by eliminating the Cosmos Master Key and has confirmed no evidence of exploitation. Security experts emphasize the importance of reviewing security postures despite the patch, as traditional tools may not detect such vulnerabilities. The incident serves as a reminder of the inherent risks in shared cloud infrastructure.

Key Points: • CosmosEscape vulnerability could compromise all databases in Azure Cosmos DB. • Attackers could acquire the Cosmos Master Key, enabling full access to databases. • Microsoft has remediated the issue, but organizations should review their security measures.

ThreatCluster AI How this analysis works

Timeline

2024-04-22
CVE-2024-27348 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
Wiz Research discloses CosmosEscape vulnerability
The vulnerability allows attackers to potentially access all databases in Azure Cosmos DB, including internal Microsoft systems.
News.Ycombinator
2026-07-30
Microsoft patches CosmosEscape vulnerability
Microsoft announced the remediation of the vulnerability, including the removal of the Cosmos Master Key.
Scworld
2026-07-30
Security experts comment on the vulnerability's impact
Experts emphasize the need for organizations to assess their security postures despite the patch, as traditional tools may not detect such vulnerabilities.
Scworld
2026-07-30
Microsoft confirms no evidence of exploitation
Following an investigation, Microsoft stated there was no unauthorized customer activity related to the vulnerability.
Feeds.4Sysops

Community

Browse all →