
Critical Azure Cosmos DB flaw threatened cross-tenant database takeover
A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security firm Wiz.
The vulnerability, dubbed CosmosEscape, relied on a chain of flaws that allowed Wiz researchers to obtain what they called the “Cosmos Master Key,” a platform-wide credential capable of retrieving the primary key for any Azure Cosmos DB account.
“Chained together, these capabilities could have enabled precis...