Microsoft has patched a critical Azure Cosmos DB vulnerability chain dubbed CosmosEscape that could have let an attacker move from a crafted Gremlin API query to code execution on a multi-tenant backend component and ultimately obtain secrets capable of accessing virtually any customer Cosmos DB account. Wiz reported that insufficient restrictions around .NET reflection allowed escape from the Gremlin sandbox, exposing a platform-wide signing secret—described as the Cosmos Master Key—and a regional account directory that could be used to locate target accounts and retrieve their primary keys.
With those primary keys, an attacker could have gained full read and write control over Cosmos DB deployments across SQL, MongoDB, Cassandra, and Gremlin APIs, including private databases across regions and potentially data tied to Microsoft services such as Entra ID, Teams, and Copilot. Microsoft said it blocked the vulnerable Gremlin entry point within 48 hours of Wiz’s November 2025 report, later completed broader fixes across all regions, removed the shared platform-wide key, and added controls to prevent similar backend access; the company said its review found no evidence of exploitation or customer data access beyond the researchers’ testing, and no customer action is required.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In July 2026, Microsoft completed broader fixes for the CosmosEscape issue across all regions and removed the platform-wide shared key. Microsoft said it also added controls to prevent similar access from the Gremlin processing environment.
Wiz reported a vulnerability chain in Azure Cosmos DB in November 2025. According to the disclosure, the chain could let an attacker escape the Gremlin query sandbox, execute code on a multi-tenant DB Gateway, expose a platform-wide signing secret, and ultimately retrieve primary keys for arbitrary customer Cosmos DB accounts.
Microsoft stated that its investigation found no unauthorized activity or exploitation beyond Wiz's controlled testing and that no customer data was accessed. The company said no customer action is required.
Microsoft blocked the vulnerable Gremlin entry point within 48 hours of Wiz's November 2025 report. This initial mitigation cut off the attack path used to escape the Gremlin environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
infoworld.com
Open sourcecsoonline.com
Open sourcesecurityweek.com
Open sourcescworld.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcewiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.