A critical vulnerability in Azure Cosmos DB's Gremlin API could have allowed attackers to obtain the Cosmos Master Key, granting access to the primary key of any Cosmos database. This would have enabled unauthorized reading and writing of sensitive data. The flaw, discovered by Google subsidiary Wiz, affects both customer and Microsoft-owned databases. If exploited, the vulnerability could have compromised the security of all Azure Cosmos DB databases, resulting in a significant breach. The discovery of this vulnerability highlights the importance of thorough security testing and vulnerability management in cloud-based services. Microsoft's prompt attention to this issue may have prevented a major security incident, but it serves as a reminder of the potential risks associated with complex cloud infrastructure1. This incident matters to practitioners because it underscores the need for rigorous security audits and testing to identify and remediate critical vulnerabilities before they can be exploited.
Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs
⚠️ Critical Alert
Why This Matters
Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both.
References
- CSO Online. (2026, July 31). Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs. CSO Online. https://www.csoonline.com/article/4203921/microsoft-almost-gave-away-the-keys-to-everyones-azure-cosmos-dbs.html
Original Source
CSO Online
Read original →