Hourly ·
CosmosEscape — Critical Azure Vulnerability Exposed Every Cosmos DB Database to Takeover
Wiz Research discovered a platform-wide master key in Azure Cosmos DB that could retrieve primary keys for any database on the service — including Microsoft's own Entra ID, Teams, and Copilot databases — all from publicly accessible endpoints.
Wiz Research has uncovered CosmosEscape, a critical vulnerability in Azure Cosmos DB — Microsoft's flagship cloud database — that could have allowed attackers to seize full read and write access to every database on the service, including Microsoft's own internal systems.
The attack chain began with a single Gremlin query. Cosmos DB's custom .NET-based Gremlin engine attempted to sandbox user queries, but researchers found the restrictions didn't account for .NET reflection. By crafting a malicious Gremlin query against their own database, the Wiz team achieved arbitrary code execution on the DB Gateway — the multi-tenant service that processes all customer queries.
From there, they discovered what they're calling the Cosmos Master Key: a platform-wide signing key that could retrieve the primary key of any Cosmos DB account across tenants, regions, and API flavors (SQL, MongoDB, Cassandra, Gremlin). Paired with the Config Store — a regional registry listing every Cosmos DB account with subscription IDs, tenant IDs, and network settings — attackers could enumerate targets at platform scale and compromise them individually, all from publicly accessible endpoints.
The blast radius extended deep into Microsoft's own stack. Services including Microsoft Entra ID, Microsoft Teams, and Microsoft Copilot all store data in Cosmos DB, and their databases were potentially reachable. Even private and network-isolated accounts were exposed, since the compromised DB Gateway enforced those isolation boundaries.
Microsoft deployed a mitigation within 48 hours of Wiz's disclosure and has since completed a major architectural migration to harden the service. The company's investigation found no evidence of exploitation beyond the researchers' controlled testing, and no customer action is required.
Notably, the discovery was assisted by Atlas, Wiz's AI vulnerability researcher — an early signal of how AI-assisted security research is beginning to reshape vulnerability discovery at cloud scale. The full exploitation chain will be presented at Black Hat USA.
Sources: Wiz Research, Hacker News
Azure中的关键CosmosEscape漏洞暴露每个Cosmos DB数据库的接管风险
Wiz Research在Azure Cosmos DB发现一个平台级主密钥,可以从服务中的任何数据库[K 获取主键——包括微软的Entra ID、Teams和Copilot数据库——从公开端点访问。
← 小時報 小時报 · 2026-07-30 16:00 UTC CosmosEscape—— Azure 存在重大漏洞 携[K 手研究揭示 Cosmos DB 平台中存在一个平台级主密钥,能够从公开访问端点获取服务[K 内包括微软自家的 Entra ID、Teams 和 Copilot 数据库在内的所有数据库的主键。W[1D[K Wiz Research 发现了Azure Cosmos DB中的一个平台级主密钥,该密钥可以用于从公共[K 端点中检索服务内的任何数据库(例如:来自微软自家的 Entra ID、Teams 和 Copil[5D[K Copilot 数据库)的主键。
More Hourlies Stories
Content on Anagnorisis is summarized, paraphrased, and editorialized from publicly available sources for length and clarity. Original sources are linked where available. All trademarks belong to their respective owners.
