< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-30T19:04:09+05:30

Azure Cosmos DB Vulnerability Allows Cross-Tenant Access via Platform-Wide Key Exposure

A critical vulnerability in Azure Cosmos DB, named CosmosEscape, allowed attackers to escape the Gremlin query sandbox and obtain platform-wide access to databases across tenants. Microsoft patched the flaw, confirming no customer data was accessed and no further action was required.

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz.

Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a

Read original article

*** END OF TRANSMISSION ***