Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Critical Flaw in Azure Cosmos DB Exposed a Platform-Wide Key, Granting Full Access to Databases Across Customer Tenants


A critical flaw in Azure Cosmos DB has been discovered, exposing a platform-wide key that could grant access to any database across customer tenants. Microsoft has taken action to address the issue, but experts are urging caution and vigilance in light of this vulnerability.

  • A vulnerability in Azure Cosmos DB, codenamed "CosmosEscape," has been discovered, allowing unauthorized access to sensitive data.
  • The bug was identified by cybersecurity firm Wiz and could have allowed attackers to escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants.
  • Microsoft confirmed that it had blocked the vulnerable entry point within 48 hours of the report, but experts raised concerns about longer-term exposure and lack of a CVE identifier or severity score.
  • The vulnerability highlights the importance of cloud security and the need for constant vigilance in the face of rapidly evolving threats.



  • A recently discovered vulnerability in Microsoft's cloud-based database service, Azure Cosmos DB, has left experts and users alike concerned about the potential for unauthorized access to sensitive data. The bug, codenamed "CosmosEscape," was identified by cybersecurity firm Wiz, which reported that it could have allowed an attacker to escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants.

    The vulnerability, which was first reported in November 2025, was discovered when researchers from Wiz crafted a malicious Gremlin query against a Gremlin database controlled by the attacker. The query, which started with a Gremlin database controlled by the attacker and credentials for that account, not access to a victim database, led to code execution on a multi-tenant gateway, exposing a platform-wide signing secret and a regional account directory.

    From there, researchers were able to locate a target database and retrieve its primary account key. The compromised gateway enforced network boundaries from inside the service, allowing the attackers to reach private and network-isolated accounts. Furthermore, the researchers claimed that they could also use the compromised gateway to change network settings and potentially access sensitive data stored in databases supporting Microsoft products such as Teams message data and Copilot.

    Microsoft confirmed that it had blocked the vulnerable Gremlin entry point within 48 hours of the report but acknowledged that the bug was not immediately discovered by its security team. The company stated that no customer data was accessed, and no customer action is required. However, experts have raised concerns about the potential for longer-term exposure and the lack of a CVE identifier or severity score.

    The vulnerability highlights the importance of cloud security and the need for constant vigilance in the face of rapidly evolving threats. Microsoft has taken steps to address the issue, including completing a fix across all regions in July 2026 and eliminating the platform-wide key. The public disclosure of this bug serves as a reminder that even seemingly secure systems can be vulnerable to exploitation.

    In an effort to provide context and clarity around the nature of this vulnerability, researchers have published technical write-ups and detailed explanations of how the exploit chain worked. These resources offer valuable insights for those seeking to understand the implications of this bug and take steps to protect themselves against similar threats in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Critical-Flaw-in-Azure-Cosmos-DB-Exposed-a-Platform-Wide-Key-Granting-Full-Access-to-Databases-Across-Customer-Tenants-ehn.shtml

  • https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html


  • Published: Thu Jul 30 10:26:59 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us