Skip to content

CosmosEscape: Vulnerability chain enabled complete access to Azure Cosmos DB

Bottom line: A chain of security vulnerabilities in Azure Cosmos DB enabled complete access to all database instances regardless of authentication.

A combination of multiple security vulnerabilities in Microsoft Azure Cosmos DB could enable attackers to gain complete access to all database instances. This vulnerability chain remained undetected for a long time and revealed fundamental weaknesses in the isolation and authentication of the database services.

The vulnerability known as CosmosEscape was not a single flaw, but rather an interplay of multiple security deficiencies in the Azure Cosmos DB architecture. This combination enabled unauthenticated attackers or attackers with limited permissions to gain complete data access to all Cosmos DB instances.

For CISOs, this represents a significant risk for all workloads that rely on Azure Cosmos DB as a central data store. Cosmos DB is frequently used for sensitive data in production environments; a vulnerability chain of this magnitude could have resulted in undetected data breaches over extended periods. The fact that multiple vulnerabilities had to work together also underscores that standard security testing may not have detected this attack chain.

Microsoft has patched the affected security vulnerabilities. Organizations should verify when patches were deployed and analyze logs from those periods for suspicious access patterns. Particular attention should be paid to database queries with unusual permissions or from unexpected source addresses. Cosmos DB environments should additionally be reviewed with stricter network isolation and enhanced audit settings.


Source: www.heise.de · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: