{"data":{"id":"9b1d605c-20b2-4680-82ed-de0c87f6f843","title":"Critical Azure Cosmos DB flaw threatened cross-tenant database takeover","summary":"A critical vulnerability in Microsoft Azure's Cosmos DB (a cloud database service) allowed attackers to escape the Gremlin sandbox (a restricted environment for running queries) and gain unauthorized access to any customer's database by obtaining a \"Cosmos Master Key\" (a platform-wide credential). The flaw affected not only customer databases but also Microsoft's own services like Teams and Copilot, and could have exposed databases even if they were network-isolated.","solution":"Microsoft blocked the vulnerable Gremlin attack path within 48 hours of being notified on November 20, 2025, and completed a broader architectural redesign across all Azure regions by July 2026. The company also eliminated the platform-wide \"Cosmos Master Key\" authentication mechanism entirely. Microsoft stated that no customer action is required.","labels":["security"],"sourceUrl":"https://www.csoonline.com/article/4204925/critical-azure-cosmos-db-flaw-threatened-cross-tenant-database-takeover.html","publishedAt":"2026-08-04T12:14:31.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Azure Cosmos DB","Microsoft Entra ID","Microsoft Teams","Microsoft Copilot"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-04T12:14:31.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}