logo

CosmosEscape: Taking Over Every Database in Azure Cosmos DB

ID: 62d87e23-d17d-5630-acf8-373e1d7f3f7f

STIX ID: report--62d87e23-d17d-5630-acf8-373e1d7f3f7f

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Yuval Avrahami

...
...

Wiz Research disclosed "CosmosEscape", a critical vulnerability in Azure Cosmos DB's Gremlin API that allowed attackers to bypass the Gremlin sandbox, execute code on the DB Gateway, and obtain a platform-wide signing secret (the "Cosmos Master Key"). Using this secret and the Config Store (a registry of all Cosmos DB accounts), an attacker could enumerate all accounts and retrieve any account's primary key, enabling full read/write access — including Microsoft internal and private/isolated databases; Microsoft has deployed mitigations and completed a long-term fix with no evidence of customer impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.