In brief: A platform-wide signing key discovered by Wiz in Azure Cosmos DB would have allowed attackers with an ordinary Azure account to access any customer database, before Microsoft fully overhauled the architecture by July 2026.
Wiz researchers found a vulnerability chain in Azure Cosmos DB called CosmosEscape that, via a platform-wide signing key, would have enabled read and write access to any customer database – even accounts that were supposedly private and network-isolated. According to Microsoft, the issue was closed with no indication that it had actually been exploited by third parties.
The starting point of the attack chain was Gremlin, the graph database query language and one of several interfaces of Azure Cosmos DB. While testing Gremlin queries, Wiz researchers encountered unusual .NET error messages, from which they concluded that Cosmos DB internally translates Gremlin queries into its own .NET code and executes them in a restricted environment. However, the restrictions in place did not adequately account for .NET reflection techniques. This allowed the researchers to achieve file read and write access, and ultimately arbitrary code execution, through their own database queries. According to Wiz, the attack required nothing more than an ordinary Azure account – created in a matter of minutes – with its own Cosmos DB Gremlin database, without any special privileges or prior access to third-party systems.
Through this escape, the researchers achieved code execution on the so-called DB Gateway, a service that processes customer queries on shared Service Fabric clusters. There they found credentials for a signing key that Wiz refers to as the Cosmos Master Key. This key was not limited to a single customer account but worked platform-wide across all tenants, regions and supported API variants such as SQL, MongoDB, Cassandra and Gremlin. Via publicly reachable endpoints, it could be used to retrieve the primary key of any Cosmos DB account. In addition, the Master Key granted access to the Config Store, a regional directory of all Cosmos DB accounts containing account names, subscription and tenant IDs, and network settings. Since the Config Store itself was queryable as a Cosmos DB database, all accounts in a region could be listed or filtered specifically for a particular organization – which, combined with the Master Key, provided a path to fully taking over third-party databases.
For CISOs using Cosmos DB, the case shows that tenant isolation in multi-tenant cloud services depends on the provider’s internal architecture and extends beyond a customer’s own configuration: even private, network-isolated accounts would have been affected, because the Master Key operated at the platform level rather than the account level. Hardening measures on the customer’s part could not have prevented this vulnerability.
Wiz reported the vulnerability to Microsoft on November 20, 2025. Just two days later, on November 22, Microsoft rolled out a hotfix that blocked the affected entry point in the Gremlin API. According to Microsoft, the complete architectural overhaul – which removed the platform-wide Master Key and strengthened inter-service authentication, network protection and monitoring capabilities – was completed across all Azure regions by July 2026. Microsoft stated that a review of access logs found no indication of unauthorized use beyond the researchers’ testing activities; customer data was not affected, and no further action is required from customers. CosmosEscape is not the first vulnerability discovered by Wiz in Azure Cosmos DB: in 2021, the company had already disclosed ChaosDB, a vulnerability exploitable via the Jupyter Notebook feature.
Source: www.it-daily.net · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.