Close Menu
    What's Hot

    Trump Says He May Drop Blanche’s Attorney General Nomination, for Now

    Wildfire in Suffolk, UK, Breaks Out a Few Miles From Nuclear Power Station

    A.I. Hedge Fund Situational Awareness Rescued by Rival Citadel

    Facebook X (Twitter) Instagram
    Trending
    • Trump Says He May Drop Blanche’s Attorney General Nomination, for Now
    • Wildfire in Suffolk, UK, Breaks Out a Few Miles From Nuclear Power Station
    • A.I. Hedge Fund Situational Awareness Rescued by Rival Citadel
    • Aston Martin investors kept in dark over details of asset shift
    • The New Friend AI Pendant Can Now Talk Back to You
    • Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
    • 2026’s UNESCO World Heritage Sites: Mount Olympus, D-Day…
    • Rescue Boat Crews Show Signs of Brain Injuries, but Coast Guard Isn’t Looking
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

    adminBy adminJuly 30, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 30, 2026Vulnerability / Cloud Security

    Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

    A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz.

    Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a multi-tenant gateway exposed a platform-wide signing secret and a regional account directory, allowing the researchers to locate a target and retrieve its primary account key.

    Microsoft blocked the vulnerable Gremlin entry point within 48 hours of the November 2025 report. Wiz said Microsoft completed the longer-term fix across all regions in July 2026 and eliminated the platform-wide key.

    “We appreciate Wiz’s work in identifying and reporting this issue through coordinated vulnerability disclosure,” a Microsoft spokesperson told The Hacker News. “We have fully addressed the issue and found no evidence of customer impact based on our investigations. We continue to invest in additional security enhancements across the platform.”

    Microsoft said its review found no unauthorized activity outside the researchers’ testing. It said no customer data was accessed and no customer action is required.

    The Hacker News has also reached out to Wiz for clarification of the exploit prerequisites and tested scope. This story will be updated with any response.

    Cybersecurity

    The published chain starts with a Gremlin database controlled by the attacker and credentials for that account, not access to a victim database.

    Microsoft’s current connection guide requires an account host, database, and graph path, and primary key before a client can submit Gremlin queries. Wiz has not published whether the exploit required anything beyond that starting point.

    According to Wiz’s technical write-up, Cosmos DB’s custom Gremlin engine translates Gremlin queries into .NET code and runs them inside a restricted environment. Wiz said the restrictions failed to account for .NET reflection, allowing the researchers to build file-read and file-write primitives before reaching arbitrary code execution.

    The public disclosure shows the output of a crafted query that executed the hostname command on the Cosmos DB backend, but not the query itself. The researchers said they will present the complete chain at a Black Hat USA briefing on August 6.

    The code execution landed on a component Wiz calls the DB Gateway, which executes customer queries on multi-tenant Azure Service Fabric clusters. Customer databases were not stored on those clusters, but the gateway could retrieve the primary key for a requested Cosmos DB account. Microsoft documentation says a Cosmos DB account primary key grants full control over all resources in that account.

    Credentials available to the gateway also provided access to a signing key that Wiz dubbed the Cosmos Master Key. Wiz said the gateway’s signing key could retrieve the primary key for any account across tenants, regions, and the SQL, MongoDB, Cassandra, and Gremlin APIs.

    The same secret opened a regional database called the Config Store, described by Wiz as a directory containing Cosmos DB account names, subscription and tenant identifiers, network settings, and tags. An attacker could use it to find a specific organization’s accounts and then request their primary keys.

    Cybersecurity

    Wiz said the chain could also reach private and network-isolated accounts because the compromised gateway enforced those network boundaries from inside the service. The researchers’ write access to the Config Store suggested network settings could also be changed, although the report does not say they demonstrated that against another customer’s account.

    Microsoft documentation says Teams message data remains in Cosmos DB, while a Microsoft engineering post says Copilot stores users’ queries and conversation histories there. Wiz said databases supporting those products were potentially accessible, but it did not report accessing their data.

    The public record does not say when the vulnerable engine and signing-key path entered production or what period Microsoft’s log review covered. The duration of potential exposure therefore remains unknown, although the known path has since been closed.

    The disclosure lists no CVE identifier or severity score. CosmosEscape is technically separate from the ChaosDB and CosMiss flaws disclosed in 2021 and 2022, which involved Cosmos DB’s Jupyter Notebook feature.

    access Azure Cosmos database Exposed flaw key PlatformWide
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article2026’s UNESCO World Heritage Sites: Mount Olympus, D-Day…
    Next Article The New Friend AI Pendant Can Now Talk Back to You
    admin
    • Website

    Related Posts

    Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

    July 30, 2026

    Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

    July 30, 2026

    Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

    July 30, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Trump Says He May Drop Blanche’s Attorney General Nomination, for Now

    Wildfire in Suffolk, UK, Breaks Out a Few Miles From Nuclear Power Station

    A.I. Hedge Fund Situational Awareness Rescued by Rival Citadel

    Aston Martin investors kept in dark over details of asset shift

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by