Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

July 30, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Azure Cosmos DB customers
Incident: A sandbox escape in the Gremlin query engine exposed a platform-wide signing secret.
Impact: Potential full read/write access to any Cosmos DB customer database regardless of tenant or region.
Attacker: Wiz researchers
Analysis: Wiz discovered a sandbox escape in the Gremlin query engine using .NET reflection to achieve arbitrary code execution on multi-tenant gateways. This breach exposed a global signing secret, known as the Cosmos Master Key, which could be used to retrieve primary account keys for any tenant across all regions. Although Microsoft has patched the flaw, the vulnerability highlights a severe risk in multi-tenant cloud architecture.
Recommendations: Review Azure Cosmos DB access logs for any unauthorized key rotations or access patterns; Implement strict network isolation and firewall rules for database endpoints; Adopt a zero-trust architecture to minimize the impact of platform-level credential theft
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *