A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a multi-tenant gateway exposed a platform-wide signing secret and a regional account directory, allowing the researchers to locate a target and retrieve its primary account key. Microsoft blocked the vulnerable Gremlin entry point within 48 hours of the November 2025 report. Wiz said Microsoft completed the longer-term fix across all regions in July 2026 and eliminated the platform-wide key. "We appreciate Wiz's work in identifying and reporting this issue through coordinated vulnerability disclosure," a Microsoft spokesperson told The Hacker News. "We have fully addressed the issue and found no evidence of customer impact based on our investigations. We continue to invest in additional security enhancements across the platform." Microsoft said its review found no unauthorized activity outside the researchers' testing. It said no customer data was accessed and no customer action is required. Wiz told The Hacker News that the only prerequisite was a standard Azure account with a Cosmos DB Gremlin database controlled by the attacker, which could be created in minutes. No special permissions, insider access, or prior foothold were required, and the exploit ran through the attacker's own database query interface. Wiz said the query returned the platform-wide master key. An attacker could then discard the original database and Azure account and use the key over Cosmos DB's public endpoint to retrieve a target account's primary key and take control of its databases. According to Wiz's technical write-up, Cosmos DB's custom Gremlin engine translates Gremlin queries
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
Read the original article
thehackernews.com →