
Microsoft Patches CosmosEscape Vulnerability in Azure Cosmos DB Gremlin API
SecurityAzureAzure Cosmos DBCosmos DBCosmosEscapeCybersecurityDatabaseMicrosoftVulnerability
Cybersecurity researchers at Wiz identified a vulnerability named CosmosEscape in Azure’s Gremlin API, which exposed a master key capable of granting unauthorized access to any Cosmos DB account. The flaw was discovered in Microsoft’s Azure Cosmos DB service, specifically within its Gremlin API component. Microsoft addressed the issue, confirming that no customer impact was observed following the fix. The vulnerability did not include a CVE ID or specific dates for discovery or patching in the reported details. CosmosEscape posed a risk of full account takeover but was mitigated before exploitation was detected.