Skip to content

Critical Vulnerability in Azure Cosmos DB Enabled Cross-Tenant Database Takeover

In brief: A vulnerability chain in Azure Cosmos DB uncovered by Wiz would have allowed, via a cross-tenant master key, access to arbitrary customer databases as well as Microsoft services such as Entra ID, Teams and Copilot, but according to Microsoft it was fully remediated without exploitation by third parties.

The security firm Wiz has disclosed a critical vulnerability in Microsoft’s Azure Cosmos DB that would have allowed attackers to break out of the Gremlin query sandbox and execute code on shared infrastructure. The credentials derived from this could have enabled access to arbitrary customer databases as well as data stores behind Microsoft services such as Entra ID, Teams and Copilot.

Wiz researchers Yuval Avrahami and Lior Maman document a chain of vulnerabilities in their report under the name CosmosEscape. The starting point was the Gremlin API, one of the query interfaces supported by Azure Cosmos DB. While testing Gremlin queries, the researchers noticed .NET exceptions indicating that Microsoft uses a custom, modified Gremlin execution engine instead of a standard implementation. Through insufficiently restricted .NET reflection, the researchers managed to break out of the Gremlin sandbox and execute arbitrary code on the Cosmos DB Database Gateway — the component that processes customer queries.

This access exposed credentials that could be used to retrieve the primary key for any Cosmos DB account, not just the researchers’ own test account. According to Wiz, the same platform credential also provided access to Cosmos DB’s regional configuration store and made it possible to enumerate database accounts by tenant or subscription ID before retrieving their primary keys. The signing key, which the researchers referred to as the “Cosmos Master Key,” was, according to Wiz, not limited to a single account but worked across tenants, regions and APIs — that is, across SQL, MongoDB, Cassandra and Gremlin interfaces.

The impact extended beyond pure customer workloads: since Cosmos DB underlies several Microsoft cloud services, databases behind Entra ID, Teams and Copilot were also potentially reachable. Even privately and network-isolated Cosmos DB instances were affected, since the compromised Database Gateway is responsible for enforcing these network boundaries.

Wiz privately reported the vulnerability to Microsoft on November 20, 2025. According to the published timeline, Microsoft blocked the vulnerable Gremlin attack path within 48 hours and completed a more comprehensive architectural redesign across all Azure regions in July 2026. Microsoft stated that its investigation found no evidence of unauthorized activity outside the researchers’ tests, that no customer data was accessed, and that customers do not need to take any action. According to the company, the platform-wide authentication mechanism that Wiz had referred to as the “Cosmos Master Key” was also eliminated.

Sakshi Grover, Senior Research Manager at IDC, contextualizes the case for CSO Online: CosmosEscape shows that tenant isolation can fail below the control planes that customers themselves configure or monitor. For security leaders, this means that the evaluation of managed database services should not rely solely on customer-side controls such as encryption, private network connectivity or identity management, but must also question the isolation guarantees of the cloud provider itself.


Source: www.csoonline.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: