Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
Read original article ↗AI Summary
A critical vulnerability in Azure Cosmos DB, dubbed CosmosEscape by Wiz, allowed attackers to escape the Gremlin query sandbox and achieve remote code execution on a multi-tenant gateway. This enabled access to a platform-wide signing key (Cosmos Master Key) and a regional account directory (Config Store), which could be used to retrieve primary account keys for any Cosmos DB account across tenants and regions. The flaw could have granted full read and write access to databases supporting services like Microsoft Teams and Copilot, though Microsoft confirmed no customer data was accessed. Microsoft patched the vulnerability within 48 hours of disclosure in November 2025, with full remediation completed by July 2026.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.