Wiz Uncovers Critical Azure Cosmos DB Flaw: One Key Could Unlock All Databases

rseroter · x · 2026-07-31

Wiz Research disclosed a critical vulnerability chain in Azure Cosmos DB dubbed CosmosEscape. Exploiting this allowed attackers to acquire the 'Cosmos Master Key', granting on-demand retrieval of any Cosmos DB account's primary key for full read/write access, alongside the ability to enumerate and target all databases on the service.

Cosmos DB is heavily used internally at Microsoft (including Entra ID, Teams, and Copilot), exposing internal databases to potential risk. Microsoft has fully remediated the issue and introduced new guardrails. Notably, the research was assisted by an early version of Atlas, Wiz's AI vulnerability researcher.

Original post →

More from Safety

Safety channel →