Microsoft fixed critical Azure Cosmos DB flaw that could have exposed any customer's database keys

Microsoft fixed a critical flaw in Azure Cosmos DB that could have let an attacker gain full read and write access to any customer's databases on the service. Wiz says the bug, dubbed CosmosEscape, let attackers escape the Gremlin API query sandbox, execute code on the database gateway, recover a platform-wide signing key, and then retrieve the primary key for any Cosmos DB account across tenants, regions, and APIs. Microsoft says it hotfixed the issue in November 2025 and completed a broader architectural fix in July 2026, with no evidence of abuse beyond the researchers' testing.
Why it matters: Organizations using Azure Cosmos DB were potentially exposed to full database compromise from a public cloud endpoint, including network-isolated deployments. Microsoft says no customer action is required, but affected teams should review Microsoft guidance, assess data exposure risk, and closely monitor Cosmos DB access logs and downstream secrets handling.

Sources

Critical Flaw Led to Azure Cosmos DB Pwnage
Ionut Arghire 2026.07.31 100% relevant
This article establishes a newly disclosed underlying event: a distinct, platform-wide Azure Cosmos DB vulnerability called CosmosEscape with Microsoft-confirmed remediation and cloud-wide impact.
← Back to all stories