Critical Azure Cosmos DB vulnerability allowed cross-tenant database access via Gremlin sandbox escape
Cloud security firm Wiz disclosed CosmosEscape, a critical vulnerability in Microsoft Azure Cosmos DB that chained multiple flaws to obtain the platform-wide Cosmos Master Key, enabling attackers to escape the Gremlin query sandbox, execute code on shared infrastructure, and access any customer database including datastores for Microsoft services such as Entra ID, Teams, and Copilot.
Topics
Sources
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.