CosmosEscape: Taking over Every Database in Azure Cosmos DB

Wiz Research discovered a critical vulnerability called 'CosmosEscape' in Azure Cosmos DB that allowed unauthorized access to internal databases. The flaw involved the Gremlin API and could have been used to compromise sensitive data across Microsoft services.
Why it matters
This highlights the severe security risks inherent in cloud infrastructure and the importance of platform-wide secret management.
Wiz Research uncovered CosmosEscape , a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack.
Through CosmosEscape, attackers could have acquired what we’ve dubbed the Cosmos Master Key - a platform-wide secret that granted two incredibly powerful capabilities:
Takeover - retrieving the primary key of any Cosmos DB account on demand, resulting in full read & write access.
Enumeration - listing all databases on the service with the ability to filter by specific organization identifiers like subscription and tenant IDs.
Chained together, these capabilities could have enabled precision targeting at platform scale: from identifying a specific organization's databases to compromising them, all from publicly accessible endpoints.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in