Azure Cosmos DB vulnerability exposed platform-wide access keys

Microsoft patched a critical flaw in Azure Cosmos DB called CosmosEscape that allowed attackers to escape the Gremlin query sandbox and gain full read/write access to any database across customer tenants using a platform-wide key. The vulnerability affected the entire Cosmos DB platform.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🤖 CosmosEscape: Azure Cosmos DB flaw (patched) let attackers escape the Gremlin query sandbox and obtain full read/write access to ANY database across customer tenants via a platform-wide key. Discov

mastodon:infosec-exchangeother61d ago kagi ↗

🤖 CosmosEscape: Azure Cosmos DB flaw (patched) let attackers escape the Gremlin query sandbox and obtain full read/write access to ANY database across customer tenants via a platform-wide key. Discovered by Wiz Research. 🔗 https:// thehackernews.com/2026/07/azur e-cosmos-db-flaw-exposed-platform.html # CVE # CloudSec # Azure # CyberSec