To the point: A security vulnerability in Azure Cosmos DB could have allowed attackers to access all customer databases — Microsoft contained the vulnerability quickly but required months for comprehensive infrastructure overhaul.
Security company Wiz discovered a critical vulnerability in the Gremlin API of Azure Cosmos DB that could have given attackers access to the master key and thus to all databases. Microsoft patched the vulnerability within two days but required eight months for a comprehensive infrastructure overhaul.
Wiz identified a critical flaw in the Gremlin API, which is responsible for managing property graph data in Azure Cosmos DB. The vulnerability could have allowed attackers to compromise the Cosmos master key and gain access to the primary keys of all Cosmos databases.
With access to the master key, threat actors would have obtained full read and write access to all Azure accounts and could have viewed a complete list of all databases in the service — including subscription and tenant IDs. Azure Cosmos DB is a NoSQL database system that underpins Microsoft’s cloud services and is accessible via SDKs for Python, Node.js, Java and .NET.
Wiz disclosed the vulnerability to Microsoft in November 2025. The software company implemented a hotfix within two days. The complete infrastructure overhaul — including removal of the Cosmos master key and introduction of new security measures — took an additional eight months.
This is not the first security risk of this kind for Cosmos DB customers: In 2021, Wiz already found a vulnerability in the data exploration tool Jupyter Notebook that allowed attackers to access database keys and other secrets.
Source: www.csoonline.com · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.