Wiz researchers find Azure Cosmos DB bug that allowed cross-tenant access

This digest was compiled by AI from multiple sources — links to the originals are below.
A vulnerability in Microsoft's Azure Cosmos DB could have allowed attackers to access any customer database, including those of Microsoft's own services, cloud security firm Wiz reported. Microsoft said it has fully fixed the issue and found no evidence of exploitation.
The CosmosEscape Exploit
Wiz researchers dubbed the vulnerability CosmosEscape, a chain of flaws that began in the Gremlin API. By exploiting insufficient .NET reflection restrictions, they escaped the Gremlin sandbox and achieved arbitrary code execution on the Cosmos DB Database Gateway. This exposed a platform-wide 'Cosmos Master Key' capable of retrieving primary keys for any Azure Cosmos DB account, regardless of tenant or region. The key functioned across SQL, MongoDB, Cassandra, and Gremlin APIs. The Database Gateway also enforces network isolation, so even private deployments were vulnerable.
Microsoft Services at Risk
Because Cosmos DB underpins Microsoft services including Entra ID, Teams, and Copilot, databases for those services were potentially accessible through the same exploit chain. Wiz also found that the compromise exposed Cosmos DB's regional configuration store, allowing enumeration of all database accounts by tenant or subscription ID. Microsoft stated that no evidence of exploitation in the wild has been found. The company blocked the vulnerable Gremlin attack path within 48 hours of Wiz's private disclosure on Nov. 20, 2025.
Microsoft's Response
Microsoft responded swiftly to Wiz's Nov. 20, 2025, private disclosure, blocking the vulnerable Gremlin attack vector within 48 hours. The company then undertook a broader architectural redesign, which was completed across all Azure regions in July 2026, fully remediating the vulnerability. Wiz researchers commended Microsoft's handling of the issue, noting that the fix was deployed without disruption to customers.