CosmosEscape Vulnerability: Critical Azure Cosmos DB Flaw
ID: 5b953786-2d71-5790-8e38-be8186924519
STIX ID: report--5b953786-2d71-5790-8e38-be8186924519
Feed Name: CyberNexora News
**CosmosEscape Vulnerability (2026)**: Security researchers at Wiz disclosed a critical vulnerability in Azure Cosmos DB's Gremlin API that permitted unrestricted .NET reflection, enabling arbitrary code execution on the Cosmos DB gateway and potential extraction of an unscoped Cosmos Master Key with risk of cross-tenant database access; Microsoft implemented architectural remediations (removing the master key and strengthening controls) and reported no evidence of active exploitation, while advising continued cloud security best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
