Critical Azure Cosmos DB vulnerability allowed cross-tenant database access via Gremlin sandbox escape

Cloud security firm Wiz disclosed CosmosEscape, a critical vulnerability in Microsoft Azure Cosmos DB that chained multiple flaws to obtain the platform-wide Cosmos Master Key, enabling attackers to escape the Gremlin query sandbox, execute code on shared infrastructure, and access any customer database including datastores for Microsoft services such as Entra ID, Teams, and Copilot.

Topics

AI securityMicrosoft

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.