Wiz disclosed ChaosDB, a critical cross-tenant vulnerability chain in Azure Cosmos DB's Jupyter Notebook feature. Misconfigurations let notebook C# code execute as root, bypass container-local firewall controls, and reach Azure instance metadata and WireServer services on shared hosts. Researchers obtained certificates and private keys, authenticated to Azure Service Fabric, and decrypted Cosmos DB primary keys, notebook tokens, and storage-account credentials belonging to other customers. The exposed Cosmos DB keys enabled persistent full read, write, and delete access to affected accounts, and Wiz reported access to databases associated with several thousand Azure customers.
Microsoft disabled the vulnerable notebook service within 48 hours of the August 2021 report and later confirmed that several thousand customers were affected; it revoked some credentials and notified more than 30% of Cosmos DB customers to rotate keys. Organizations with Jupyter Notebooks enabled—especially accounts permitting external or cross-tenant network access—were advised to regenerate primary keys, restrict network exposure, move from shared keys to RBAC, and use private endpoints. Wiz later used ChaosDB to introduce PEACH, a tenant-isolation assessment framework covering Privilege, Encryption, Authentication, Connectivity, and Hygiene to identify and harden cross-tenant boundaries in cloud applications.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed that several thousand customers were affected by the ChaosDB issue.
Microsoft Security Response Center confirmed the reported behavior, and Wiz observed that some credentials obtained during its research were revoked the same day.
Microsoft disabled the vulnerable Cosmos DB Jupyter Notebook service after Wiz's report, pending a security redesign.
Wiz notified Microsoft about ChaosDB, a cross-tenant vulnerability chain that could expose Cosmos DB primary keys and grant full read, write, and delete access to affected customer accounts.
Wiz first exploited flaws in Cosmos DB's Jupyter Notebook environment, escalating to root, bypassing container firewall rules, and obtaining access to shared-host Azure services and credentials. The researchers ultimately accessed other customers' Cosmos DB keys and infrastructure data.
Microsoft began automatically enabling the Jupyter Notebook feature for newly created Cosmos DB accounts. The feature would be automatically disabled if unused during its initial three-day period.
Microsoft introduced the Jupyter Notebook feature for Azure Cosmos DB, enabling customers to visualize data and create customized views.
Wiz introduced PEACH, a framework for assessing tenant isolation in multi-tenant cloud applications across privilege, encryption, authentication, connectivity, and hygiene controls. Wiz retrospectively applied it to ChaosDB and identified isolation-design and implementation gaps that enabled the attack path.
Microsoft notified more than 30% of Cosmos DB customers that they needed to manually rotate access keys, while Wiz urged potentially exposed customers to regenerate keys because primary keys could have been retained by attackers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
peach.wiz.io
Open sourcewiz.io
Open sourceyoutube.com
Open sourcewiz.io
Open sourcewiz.io
Open sourcewiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.