Azure Cosmos DB Flaw Exposes Critical Security Gaps for Enterprises
A recently identified vulnerability in Microsoft Azure’s Cosmos DB service raised alarms about potential risks to customer data security. This critical flaw, termed CosmosEscape, might have enabled attackers to break free from the confines of the Gremlin query sandbox, execute malicious code on shared infrastructure, and access databases across multiple tenants, including those utilized by Microsoft applications such as Entra ID, Teams, and Copilot.
Research from cloud security firm Wiz unveils that the exploit stemmed from a series of weaknesses that ultimately allowed them to obtain the so-called “Cosmos Master Key.” This key serves as a high-level credential with the power to fetch the primary key for any Azure Cosmos DB account.
Wiz researchers, Yuval Avrahami and Lior Maman, articulated in their analysis, “Chained together, these capabilities could have enabled precision targeting at platform scale: from identifying a specific organization’s databases to compromising them, all from publicly accessible endpoints.”
Identifying Vulnerabilities in the Query Engine
The investigation traced the vulnerability back to the Gremlin API, one of Azure Cosmos DB's query interfaces. During their experimentation with Gremlin queries, researchers detected .NET exceptions, indicating that Microsoft utilized a custom execution engine instead of a standard version. This deviation provided enough leeway for them to exploit inadequate restrictions associated with .NET reflection, allowing them to escape the Gremlin sandbox.
By breaching this environment, unauthorized access was granted to the Cosmos DB Database Gateway, enabling researchers to harness credentials that could retrieve primary keys from any Cosmos DB account—not just their own. Further complicating matters, the same credential was tied to Cosmos DB’s regional configuration store, which permitted the cataloging of database accounts linked to various tenants and subscription IDs before extracting their primary keys.
Wiz noted that this signing key's scope extended across tenants, regions, and various API formats, including SQL, MongoDB, and Cassandra. “We soon discovered the signing key wasn’t scoped to a single account,” they stated.
The implications extend beyond individual customer databases. Several key Microsoft services rely on Cosmos DB, implying that databases serving platforms like Entra ID, Teams, and Copilot could theoretically be compromised. Even private deployments isolated from public access were at risk, as the compromised Database Gateway handled the enforcement of network boundaries.
Microsoft Responds to the Threat
Wiz communicated its findings to Microsoft on November 20, 2025. Within a mere 48 hours, the software giant blocked the vulnerable pathway associated with the Gremlin API and initiated a comprehensive architectural overhaul that spanned all Azure regions, culminating in July 2026.
As confirmation of their thorough response, Microsoft stated in their disclosure that investigations revealed no unauthorized activity nor evidence that customer data had been exposed. They reassured users that no action on their part was necessary, saying, “No customer action is required.”
Furthermore, Wiz highlighted that the platform-wide authentication mechanism known as the “Cosmos Master Key” had been effectively eliminated post-remediation. Microsoft has yet to provide additional comments on the matter.
Implications for Enterprise Security
Despite Microsoft’s reassurances, the incident underscores vulnerabilities that may exist outside the customers' direct control, a point emphasized by Sakshi Grover, senior research manager at IDC. “CosmosEscape demonstrates that tenant isolation can fail below layers that customers are able to configure or monitor,” she noted.
This revelation urges enterprises to shift their evaluation of managed database services. It's no longer sufficient to focus solely on features like encryption and private networking. Organizations must now scrutinize how their providers isolate tenant-controlled execution from high-level service components and ensure robust credential management is in place.
Grover pointed out that organizations utilizing the Cosmos DB Gremlin API should carefully review their logs to determine if any sensitive workloads experienced impacts and seek clarification from Microsoft where necessary, especially for compliance or regulatory obligations.
In a broader context, this incident serves as a reminder for businesses to minimize dependency on static database account keys and consider adopting managed identities, fine-grained role-based access controls, and client-side encryption wherever feasible. The vulnerability showcases the pressing need to examine privilege boundaries within extensive cloud infrastructures.
“Hyperscale services operate on privileged gateways, control planes, and metadata stores that manage various customers,” Grover concluded. “Whenever tenant-controlled inputs are processed near these components, vulnerability can traverse perceived security boundaries and result in widespread ramifications.”