Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [cyber, digest-2026-07-31, azure, cosmos-db, cloud-security, sandbox-escape, vulnerability] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Azure Cosmos DB 'CosmosEscape' Flaw Exposed Platform-Wide Key Across All Tenants

Summary

Wiz disclosed a now-patched vulnerability chain in Azure Cosmos DB dubbed CosmosEscape that could have let an attacker escape the Gremlin query sandbox and obtain full read/write access to databases across customer tenants. The exploit chain involved a crafted Gremlin query achieving code execution on a multi-tenant gateway, exposing a platform-wide signing secret and a regional account directory, enabling researchers to locate a target and retrieve its primary account key.

Key Details

  • Date: 2026-07-30
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Discoverer: Wiz Research
  • Vulnerability Type: Sandbox escape โ€” multi-tenant
  • Attack Vector: Crafted Gremlin query โ†’ code execution on multi-tenant gateway
  • Exposed Data: Platform-wide signing secret, regional account directory, primary account keys
  • Microsoft Response: Blocked vulnerable Gremlin entry point within 48 hours of November 2025 report; full fix across all regions completed July 2026
  • Risk: Full read/write access to databases across customer tenants

Source

See Also

  • CISA Adds One New Known Exploited Vulnerability to KEV Catalogue
  • CISA Publishes Open Source Software Security Principles and Practices