Skip to content

Microsoft: Critical Authentication Gap in Azure Cosmos DB Identified

The gist: An authentication gap in Azure Cosmos DB would have given attackers full access to all databases in the service, including those of Microsoft itself.

Security researchers have discovered a critical vulnerability in Microsoft’s Azure Cosmos DB that would have allowed attackers to access and manipulate all databases with a single key.

Security researchers have identified and reported a vulnerability in Azure Cosmos DB, Microsoft’s managed database service. The affected authentication mechanism would have allowed attackers to gain complete access to all databases in the service with a single key — both customer instances and Microsoft’s own systems.

The gap affected authentication and authorization within Azure Cosmos DB. Had an attacker obtained or exploited this universal key, it would have been possible to read, modify, and delete database contents across tenants. This would have had significant implications for the data security and integrity of all affected customers.

After the vulnerability was reported by security researchers, Microsoft initiated measures to remediate it. Details on remediation and the exact timeline of the patch release were not available at the time of initial reporting.


Source: www.golem.de · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: