
CosmosEscape Flaw Enabled Cross-Tenant Takeover of Azure Cosmos DB Accounts
Wiz Research disclosed a critical vulnerability, dubbed CosmosEscape, in Azure Cosmos DB, Microsoft’s flagship NoSQL database service. The flaw resided in the service’s Gremlin API and could have allowed attackers to compromise any database on the platform, including Microsoft’s own internal Cosmos DB instances powering services like Microsoft Entra ID, Microsoft Teams, and Microsoft Copilot. […]
The post CosmosEscape Flaw Enabled Cross-Tenant Takeover of Azure Cosmos DB Accounts appeared first on Cyber Security News.