A now-patched flaw in Azure Cosmos DB could have let an attacker break out of the Gremlin query sandbox and gain cross-tenant read and write access through a chain Wiz named CosmosEscape. Microsoft says it fixed the issue, removed the platform-wide key, and found no evidence of customer impact or unauthorized activity. #AzureCosmosDB #CosmosEscape #Wiz
Keypoints
- Wiz discovered a chain that could escape the Gremlin sandbox in Azure Cosmos DB.
- The exploit path led to code execution on a multi-tenant gateway.
- The gateway exposed a platform-wide signing secret and regional account directory.
- An attacker could potentially retrieve primary keys for Cosmos DB accounts across tenants and regions.
- Microsoft blocked the entry point quickly and later removed the shared key across all regions.
Read More: https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html