{"id":16551,"date":"2026-08-04T12:16:26","date_gmt":"2026-08-04T12:16:26","guid":{"rendered":"https:\/\/newestek.com\/?p=16551"},"modified":"2026-08-04T12:16:26","modified_gmt":"2026-08-04T12:16:26","slug":"critical-azure-cosmos-db-flaw-threatened-cross-tenant-database-takeover","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16551","title":{"rendered":"Critical Azure Cosmos DB flaw threatened cross-tenant database takeover"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">A critical vulnerability in Microsoft Azure\u2019s Cosmos DB database service could have enabled attackers to escape the platform\u2019s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer\u2019s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security firm Wiz.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability, dubbed CosmosEscape, relied on a chain of flaws that allowed Wiz researchers to obtain what they called the \u201cCosmos Master Key,\u201d a platform-wide credential capable of retrieving the primary key for any Azure Cosmos DB account.<\/p>\n<p class=\"wp-block-paragraph\">\u201cChained together, these capabilities could have enabled precision targeting at platform scale: from identifying a specific organization\u2019s databases to compromising them, all from publicly accessible endpoints,\u201d Wiz researchers Yuval Avrahami and Lior Maman wrote in a <a href=\"https:\/\/www.wiz.io\/blog\/cosmosescape-taking-over-every-database-in-azure-cosmos-db\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"exploiting-the-services-query-engine\">Exploiting the service\u2019s query engine<\/h2>\n<p class=\"wp-block-paragraph\">According to Wiz, the attack originated in the Gremlin API, one of several query interfaces supported by Azure Cosmos DB. While testing Gremlin queries, the researchers observed .NET exceptions suggesting Microsoft was using a custom Gremlin execution engine rather than a standard implementation.<\/p>\n<p class=\"wp-block-paragraph\">The researchers found they could exploit insufficient restrictions around .NET reflection to escape the Gremlin sandbox and achieve arbitrary code execution on the Cosmos DB Database Gateway, the service responsible for executing customer queries.<\/p>\n<p class=\"wp-block-paragraph\">That access exposed credentials capable of retrieving the primary key for any Cosmos DB account\u2014not just the researchers\u2019 own database. According to Wiz, the same platform credential also unlocked Cosmos DB\u2019s regional configuration store, allowing attackers to enumerate database accounts by tenant or subscription ID before retrieving their primary keys.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe soon discovered the signing key wasn\u2019t scoped to a single account,\u201d Wiz said in its blog. \u201cIt worked across tenants, regions, and even API flavors \u2014 SQL, MongoDB, Cassandra, and Gremlin.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The researchers added that the exploit chain affected more than just customer workloads. Because Cosmos DB underpins several Microsoft cloud services, databases supporting Microsoft Entra ID, Teams, and Copilot were also potentially accessible. Private and network-isolated Cosmos DB deployments were likewise exposed because the compromised Database Gateway was responsible for enforcing those network boundaries, the blog added.<\/p>\n<h2 class=\"wp-block-heading\" id=\"microsoft-says-no-evidence-of-exploitation\">Microsoft says no evidence of exploitation<\/h2>\n<p class=\"wp-block-paragraph\">Wiz said it privately disclosed the vulnerability to Microsoft on Nov. 20, 2025. According to the published disclosure timeline, Microsoft blocked the vulnerable Gremlin attack path within 48 hours before completing a broader architectural redesign across all Azure regions in July 2026.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft has since fully remediated the vulnerability. In a statement published alongside Wiz\u2019s disclosure, the company said its investigation found no evidence of unauthorized activity beyond the researchers\u2019 testing, that no customer data was accessed, and that no customer action is required.<\/p>\n<p class=\"wp-block-paragraph\">\u201cNo customer action is required,\u201d the blog added, quoting Microsoft.<\/p>\n<p class=\"wp-block-paragraph\">Wiz said Microsoft also eliminated the platform-wide authentication mechanism it dubbed the \u201cCosmos Master Key.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Microsoft did not immediately respond to a request for additional comment.<\/p>\n<h2 class=\"wp-block-heading\" id=\"enterprises-should-examine-provider-isolation\">Enterprises should examine provider isolation<\/h2>\n<p class=\"wp-block-paragraph\">While Microsoft said customers do not need to take any immediate action, the disclosure highlights risks that exist below the security controls cloud customers typically manage themselves, said Sakshi Grover, senior research manager at IDC.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCosmosEscape demonstrates that tenant isolation can fail below the layers customers are able to configure or monitor,\u201d Grover said.<\/p>\n<p class=\"wp-block-paragraph\">Rather than evaluating managed database services primarily on features such as encryption, private networking, or identity controls, enterprises should examine how providers isolate tenant-controlled execution from privileged service components, scope internal credentials, and contain the impact if shared infrastructure is compromised, she said.<\/p>\n<p class=\"wp-block-paragraph\">Grover said Microsoft\u2019s assessment should carry significant weight because only the company has visibility into its service-plane telemetry. However, organizations using the Cosmos DB Gremlin API should review available logs, determine whether sensitive workloads were affected, and seek additional assurance from Microsoft where regulatory or compliance requirements demand it.<\/p>\n<p class=\"wp-block-paragraph\">The incident should also prompt organizations to reduce long-term reliance on static database account keys by adopting managed identities, fine-grained role-based access controls, and client-side encryption where practical, she said.<\/p>\n<p class=\"wp-block-paragraph\">More broadly, Grover said the vulnerability illustrates the importance of scrutinizing privilege boundaries within hyperscale cloud platforms.<\/p>\n<p class=\"wp-block-paragraph\">\u201cHyperscale services often depend on privileged gateways, control planes, metadata stores and service identities that operate across large numbers of customers,\u201d she said. \u201cWhenever tenant-controlled input is processed close to those components, a vulnerability can cross what appeared to be separate security boundaries and create platform-scale consequences.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A critical vulnerability in Microsoft Azure\u2019s Cosmos DB database service could have enabled attackers to escape the platform\u2019s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer\u2019s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security firm Wiz. The vulnerability, dubbed CosmosEscape, relied on a chain&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16551\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16551","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16551"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16551\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}