Wiz researchers find Azure Cosmos DB bug that allowed cross-tenant access
This digest was compiled by AI from multiple sources — links to the originals are below.

A vulnerability in Microsoft's Azure Cosmos DB could have allowed attackers to access any customer database, including those of Microsoft's own services, cloud security firm Wiz reported. Microsoft said it has fully fixed the issue and found no evidence of exploitation.
The CosmosEscape Exploit
Wiz researchers dubbed the vulnerability CosmosEscape, a chain of flaws that began in the Gremlin API. By exploiting insufficient .NET reflection restrictions, they escaped the Gremlin sandbox and achieved arbitrary code execution on the Cosmos DB Database Gateway. This exposed a platform-wide 'Cosmos Master Key' capable of retrieving primary keys for any Azure Cosmos DB account, regardless of tenant or region. The key functioned across SQL, MongoDB, Cassandra, and Gremlin APIs. The Database Gateway also enforces network isolation, so even private deployments were vulnerable.
Microsoft Services at Risk
Because Cosmos DB underpins Microsoft services including Entra ID, Teams, and Copilot, databases for those services were potentially accessible through the same exploit chain. Wiz also found that the compromise exposed Cosmos DB's regional configuration store, allowing enumeration of all database accounts by tenant or subscription ID. Microsoft stated that no evidence of exploitation in the wild has been found. The company blocked the vulnerable Gremlin attack path within 48 hours of Wiz's private disclosure on Nov. 20, 2025.
Microsoft's Response
Microsoft responded swiftly to Wiz's Nov. 20, 2025, private disclosure, blocking the vulnerable Gremlin attack vector within 48 hours. The company then undertook a broader architectural redesign, which was completed across all Azure regions in July 2026, fully remediating the vulnerability. Wiz researchers commended Microsoft's handling of the issue, noting that the fix was deployed without disruption to customers.
What's Next
The incident highlights the systemic risks of shared multi-tenant cloud infrastructure, where a single bug can expose vast numbers of customers. It remains unclear whether similar vulnerabilities exist in other cloud database services that rely on custom query engines.
1 source
Wiz researchers find Azure Cosmos DB bug that allowed cross-tenant access



