Microsoft patched a critical Azure Cosmos DB vulnerability that researchers said could have enabled cross-tenant database takeover by exposing a platform-wide signing secret. Wiz, which dubbed the exploit chain CosmosEscape, reported that an attacker with only a standard Azure account and an attacker-controlled Cosmos DB Gremlin database could escape the Gremlin query sandbox, achieve code execution on a multi-tenant gateway, and obtain a key capable of accessing other customers’ databases.
According to the disclosure, the exposed secret could be used to retrieve primary account keys across tenants, regions, and multiple Cosmos DB API variants, including SQL, MongoDB, Cassandra, and Gremlin, potentially affecting even private or network-isolated accounts. Microsoft said it blocked the vulnerable Gremlin input within 48 hours of disclosure in November 2025, completed a permanent global fix in July 2026, and removed the platform-wide key; the company added that it found no evidence of customer impact or unauthorized activity beyond the researchers’ testing and said no customer action was required.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
In July 2026, Microsoft finished a permanent fix for the Azure Cosmos DB vulnerability across all regions. As part of the remediation, it removed the platform-wide key that enabled cross-tenant access.
Within 48 hours of Wiz's November 2025 report, Microsoft blocked the vulnerable Gremlin input used in the exploit chain. This was an initial mitigation to stop exploitation while broader remediation continued.
In November 2025, Wiz disclosed the CosmosEscape exploit chain to Microsoft. The chain allowed sandbox escape in the Gremlin query engine, code execution on a multi-tenant gateway, and exposure of a platform-wide signing secret that could be used to access other tenants' databases.
Public reporting described the flaw as a critical Azure Cosmos DB vulnerability that threatened cross-tenant database takeover. Coverage tied the issue to the now-patched weakness in Cosmos DB's Gremlin functionality.
Wiz said it would present the full CosmosEscape exploit chain at Black Hat USA on August 6. Public disclosure at that point showed only the result of a crafted query executing the hostname command on a Cosmos DB backend system.
After investigating the issue, Microsoft said it found no evidence that customers were affected and no unauthorized activity beyond the researchers' testing. The company also said no customer action was required.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcemkd-cirt.mk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.