logo

Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB to Potential Attacks

ID: 97eb6053-80b1-52e9-8e0a-88551d89575a

STIX ID: report--97eb6053-80b1-52e9-8e0a-88551d89575a

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-30

Date Updated: 2026-08-05

...
...

**Executive Summary:** Wiz Research disclosed a critical vulnerability called CosmosEscape in Azure Cosmos DB’s Gremlin API that could have allowed attackers to obtain the Cosmos Master Key and gain full read/write access to all databases (including Microsoft internal services); Microsoft has remediated the issue and reports no evidence of exploitation, but organizations should review their security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.