Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Major Vulnerability in Azure Cosmos DB Exposed

Major Vulnerability in Azure Cosmos DB Exposed

Posted on July 31, 2026 By CWS

An alarming security flaw in Microsoft’s Azure Cosmos DB was uncovered by cybersecurity firm Wiz, revealing a potential threat to all databases within the service. This vulnerability, termed ‘CosmosEscape,’ could have granted attackers full access to any database by exploiting a platform-wide key.

Security Flaw Details

The CosmosEscape flaw allowed malicious actors to retrieve the primary key of any Cosmos DB account, enabling comprehensive read and write access. With these privileges, attackers could list and filter databases by organizational identifiers such as subscription and tenant IDs. This capability posed a significant risk, allowing for targeted attacks on specific organizations.

Wiz highlighted that the issue was serious due to Microsoft’s integration of Cosmos DB across services like Entra ID, Teams, and Copilot. This integration could have exposed sensitive data to unauthorized access if the vulnerability was exploited.

Exploiting the Gremlin API

The vulnerability was linked to the Gremlin API, a popular graph query language. The API relies on a custom engine that compiles queries into .NET code. Although restrictions were in place to prevent unauthorized access, Wiz found that .NET reflection could bypass these, allowing arbitrary code execution.

This discovery enabled Wiz to gain code execution on the DB Gateway, a service operating on multi-tenant clusters. The gateway used a signing key for accessing customer accounts’ primary keys, which was effective across various scopes including tenants and APIs.

Microsoft’s Response and Mitigation

Upon detecting the flaw, Wiz reported it to Microsoft in November 2025. The tech giant swiftly implemented a hotfix within two days to mitigate the vulnerability. By July, Microsoft had completed a long-term architectural update across all regions to enhance security.

Microsoft assured that extensive log reviews showed no unauthorized access beyond the controlled testing by researchers. Consequently, no customer data was compromised, and no further action is required by users. This response underscores the importance of rapid detection and remediation in cloud security.

This incident highlights the critical need for robust cybersecurity measures in cloud services, especially those holding vast amounts of sensitive data. As cloud technology continues to evolve, ongoing vigilance and proactive security updates remain paramount to safeguarding user data.

Security Week News Tags:Azure, cloud security, code execution, Cosmos DB, Cybersecurity, database security, Gremlin API, Microsoft, Vulnerability, Wiz

Post navigation

Previous Post: CareCloud Data Breach Affects 350,000 Individuals
Next Post: Anthropic AI Models Breach Security Systems in Test

Related Posts

Feds Seize Password Database Used in Massive Bank Account Takeover Scheme Feds Seize Password Database Used in Massive Bank Account Takeover Scheme Security Week News
Ukrainian Man Admits Guilt in US for Conti Ransomware Ukrainian Man Admits Guilt in US for Conti Ransomware Security Week News
OpenClaw Flaw Could Allow AI Takeover via Malicious Sites OpenClaw Flaw Could Allow AI Takeover via Malicious Sites Security Week News
Chrome, Edge Extensions Caught Stealing ChatGPT Sessions Chrome, Edge Extensions Caught Stealing ChatGPT Sessions Security Week News
Depthfirst Raises  Million for Vulnerability Management Depthfirst Raises $40 Million for Vulnerability Management Security Week News
Hackers Target Casino Operator Boyd Gaming Hackers Target Casino Operator Boyd Gaming Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark