Critical Azure Cosmos DB Flaw Exposed
Security researchers at Wiz have uncovered CosmosEscape, a critical vulnerability in Microsoft Azure Cosmos DB that could have allowed attackers to gain unauthorized access to virtually every database hosted on the platform. The flaw, discovered through Cosmos DB's Gremlin API, had the potential to compromise Microsoft's own cloud services, including Microsoft Entra ID, Microsoft Teams, and Microsoft Copilot, all of which rely on Cosmos DB.
According to Wiz Research, the vulnerability enabled attackers to extract a highly privileged Cosmos Master Key, which could retrieve the primary keys of any Cosmos DB account and enumerate databases across the platform using subscription or tenant identifiers. Chaining these capabilities together could have enabled large-scale, targeted attacks against organizations through publicly accessible endpoints.
The exploit stemmed from weaknesses in Cosmos DB's custom .NET-based Gremlin query engine. Researchers found that insufficient restrictions on .NET reflection allowed specially crafted Gremlin queries to bypass the intended sandbox, enabling file access and ultimately arbitrary code execution on Cosmos DB's backend infrastructure.
Microsoft has fully remediated the vulnerability by eliminating the Cosmos Master Key and introducing additional security guardrails to prevent similar attacks. After a comprehensive investigation, the company stated it found no evidence of customer exploitation beyond the responsible research conducted by Wiz.
The discovery highlights the growing importance of securing cloud-native services and demonstrates how sophisticated vulnerabilities in managed cloud platforms can potentially affect millions of enterprise workloads if left unaddressed.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




