< Back to all clusters
[TECHNOLOGY] · United States · 4 sources

Microsoft Azure Cosmos DB flaw found by Wiz could have exposed thousands of cloud customers

Wiz security researchers identified a critical vulnerability in Microsoft Azure Cosmos DB, dubbed "CosmosEscape," that exploited a flaw in the service's Gremlin API and .NET reflection handling. The bug could have allowed attackers to execute arbitrary code, seize the Cosmos Master Key and gain unrestricted access to any tenant's data, potentially compromising millions of workloads and Microsoft’s own internal systems.

Microsoft confirmed the issue was fully patched in cooperation with Wiz and reported no evidence of customer impact. The flaw follows earlier Cosmos DB vulnerabilities discovered in 2021 and 2022 that also required rapid remediation. Security experts warned that such multi‑tenant cloud weaknesses pose systemic risks, but the prompt patching mitigated the immediate danger.

Entities: Azure Cosmos DB · CosmosEscape vulnerability · Microsoft Corporation · Wiz