A critical flaw in Microsoft Azure's Cosmos DB database service, known as CosmosEscape, posed a significant threat to the security of customer databases, including those used by Microsoft services such as Entra ID, Teams, and Copilot. This vulnerability allowed attackers to break out of the Gremlin query sandbox and execute code on shared infrastructure, potentially granting access to any customer's database. The CosmosEscape flaw relied on a chain of exploits that enabled researchers to obtain a platform-wide credential, dubbed the "Cosmos Master Key"1. This master key would have granted attackers unrestricted access to Cosmos DB databases, compromising the confidentiality and integrity of sensitive data. The severity of this vulnerability underscores the importance of robust security testing and vulnerability management in cloud-based database services, so what matters most to practitioners is the need for continuous monitoring and remediation of potential security flaws to prevent such threats.
Critical Azure Cosmos DB flaw threatened cross-tenant database takeover
⚡ High Priority
Why This Matters
A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared.
References
- Wiz. (2026, August 4). Critical Azure Cosmos DB flaw threatened cross-tenant database takeover. CSO Online. https://www.csoonline.com/article/4204925/critical-azure-cosmos-db-flaw-threatened-cross-tenant-database-takeover.html
Original Source
CSO Online
Read original →