type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [cyber, digest-2026-07-31, azure, cosmos-db, cloud-security, sandbox-escape, vulnerability] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
Azure Cosmos DB 'CosmosEscape' Flaw Exposed Platform-Wide Key Across All Tenants
Summary
Wiz disclosed a now-patched vulnerability chain in Azure Cosmos DB dubbed CosmosEscape that could have let an attacker escape the Gremlin query sandbox and obtain full read/write access to databases across customer tenants. The exploit chain involved a crafted Gremlin query achieving code execution on a multi-tenant gateway, exposing a platform-wide signing secret and a regional account directory, enabling researchers to locate a target and retrieve its primary account key.
Key Details
- Date: 2026-07-30
- Source: The Hacker News
- Reliability: Tier 2/4 โ Established cyber journalism
- Discoverer: Wiz Research
- Vulnerability Type: Sandbox escape โ multi-tenant
- Attack Vector: Crafted Gremlin query โ code execution on multi-tenant gateway
- Exposed Data: Platform-wide signing secret, regional account directory, primary account keys
- Microsoft Response: Blocked vulnerable Gremlin entry point within 48 hours of November 2025 report; full fix across all regions completed July 2026
- Risk: Full read/write access to databases across customer tenants
Source
See Also
- CISA Adds One New Known Exploited Vulnerability to KEV Catalogue
- CISA Publishes Open Source Software Security Principles and Practices