A critical vulnerability in Azure Cosmos DB's Gremlin API could have allowed attackers to obtain the Cosmos Master Key, granting access to the primary key of any Cosmos database. This would have enabled unauthorized reading and writing of sensitive data. The flaw, discovered by Google subsidiary Wiz, affects both customer and Microsoft-owned databases. If exploited, the vulnerability could have compromised the security of all Azure Cosmos DB databases, resulting in a significant breach. The discovery of this vulnerability highlights the importance of thorough security testing and vulnerability management in cloud-based services. Microsoft's prompt attention to this issue may have prevented a major security incident, but it serves as a reminder of the potential risks associated with complex cloud infrastructure1. This incident matters to practitioners because it underscores the need for rigorous security audits and testing to identify and remediate critical vulnerabilities before they can be exploited.