Bottom line: A flaw in Azure Cosmos DB made it possible to access platform-wide keys through a manipulated Gremlin query and gain access to all customer tenants.
A now-patched security vulnerability in Azure Cosmos DB could have allowed attackers to bypass the sandbox of the Gremlin query engine and access databases of all customer instances. The security company Wiz named the exploit chain “CosmosEscape”.
The vulnerability was based on an exploit chain that began with a manipulated query against a Gremlin database controlled by the attacker. This enabled code execution, which in turn provided access to platform-wide valid keys that could be used to read and write access to arbitrary databases across customer boundaries.
For a CISO, this vulnerability represented a significant risk of data acquisition: Azure Cosmos DB users had no technical control over data access, since the exploit was located at the Azure platform level. An attacker with access to any customer’s Gremlin database could thus gain full access to sensitive data of all other customers — completely independent of the access control measures configured there.
Microsoft has since closed the gap. The need for this remediation underscores the importance of regular security audits for managed database services and monitoring of vendor security announcements, particularly for highly privileged, platform-wide usable keys. Organizations using Azure Cosmos DB should verify that the current version of the patch has been deployed.
Source: thehackernews.com · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.