Critical Azure Cosmos DB flaw threatened cross-tenant database takeover
Summary
A critical vulnerability in Microsoft Azure's Cosmos DB (a cloud database service) allowed attackers to escape the Gremlin sandbox (a restricted environment for running queries) and gain unauthorized access to any customer's database by obtaining a "Cosmos Master Key" (a platform-wide credential). The flaw affected not only customer databases but also Microsoft's own services like Teams and Copilot, and could have exposed databases even if they were network-isolated.
Solution / Mitigation
Microsoft blocked the vulnerable Gremlin attack path within 48 hours of being notified on November 20, 2025, and completed a broader architectural redesign across all Azure regions by July 2026. The company also eliminated the platform-wide "Cosmos Master Key" authentication mechanism entirely. Microsoft stated that no customer action is required.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.csoonline.com/article/4204925/critical-azure-cosmos-db-flaw-threatened-cross-tenant-database-takeover.html
First tracked: August 4, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 85%