Critical Azure Cosmos DB Vulnerability Exploited

www.news4hackers.com-critical-azure-cosmos-db-vulnerability-exploited-critical-azure-cosmos-db-vulnerability-exploited

A severe security flaw in the Azure Cosmos DB database service could have enabled attackers to access all databases hosted on the platform, according to cybersecurity firm Wiz.

According to cybersecurity firm Wiz.

Overview of the Vulnerability

The vulnerability, designated as CosmosEscape, allowed threat actors to obtain a platform-wide key capable of retrieving the primary key for any Cosmos DB account, granting unrestricted read and write access across the service. This would have enabled adversaries to identify and compromise databases belonging to specific organizations by leveraging subscription and tenant identifiers.

Technical Details

The flaw exploited a critical weakness in the Gremlin API, a graph query language used to interact with Cosmos DB. The API relies on a custom Gremlin engine that compiles queries into .NET code executed within a sandboxed environment. Wiz researchers discovered that bypassing the sandbox’s restrictions provided code execution on the DB Gateway, a service responsible for processing customer queries on behalf of users. This gateway operated within multi-tenant Service Fabric clusters, making it a high-value target.

Key Components of the Exploit

The researchers identified that the DB Gateway utilized a signing key to access primary keys for customer accounts. This key functioned across all tenants, regions, and APIs, effectively acting as a “Cosmos Master Key.” With this key, attackers could access a configuration store containing metadata for every Cosmos DB account, including names, subscription IDs, and tenant identifiers. The configuration store itself was a Cosmos DB database, allowing adversaries to query it using the service’s SQL engine. This capability would have enabled attackers to enumerate all accounts in a given region or filter databases by tenant ID to target specific organizations.

Microsoft’s Response

The vulnerability was disclosed to Microsoft in November 2025, prompting the company to deploy a hotfix within two days to block the attack vector. A permanent architectural fix was fully implemented across all regions by July 2026. Microsoft confirmed that no unauthorized activity was detected beyond the researchers’ testing and stated that no customer action was required.

Implications and Lessons Learned

The flaw highlighted risks associated with shared infrastructure and the potential for cascading impacts across interconnected services. Microsoft’s response underscored the importance of rapid patching and architectural hardening to mitigate widespread exposure. The incident also emphasized the need for continuous monitoring of multi-tenant environments to detect and neutralize threats before they can be exploited at scale.

Conclusion

While no actual breaches were reported, the CosmosEscape vulnerability serves as a critical reminder of the challenges in securing complex, multi-tenant cloud systems. It underscores the necessity of proactive security measures, transparent communication, and swift remediation to protect against emerging threats.



About Author

en_USEnglish