Technology News

Azure Cosmos DB Vulnerability Threatened Multi‑Tenant Access

A recently patched flaw in Azure Cosmos DB could have let attackers escape the Gremlin query sandbox and gain read/write access to all databases in customer tenants, Wiz reports.

Microsoft Azure’s Cosmos DB, a globally distributed database service, recently disclosed a critical flaw that could let attackers bypass the Gremlin query sandbox and gain unrestricted access to customer data.

In a public statement, security firm Wiz outlined the vulnerability, codenamed CosmosEscape, highlighting how a crafted Gremlin query could trigger arbitrary code execution on the underlying host.

The attack chain begins with a specially crafted query against a Gremlin database that the attacker controls. Once the query runs, the sandbox is compromised, allowing the attacker to run native code.

With native code execution, the attacker can elevate privileges and read or write any database in the tenant, effectively breaking the isolation that Cosmos DB provides between customers.

Wiz noted that the flaw could affect all tenants that use the affected Cosmos DB version, making it a platform‑wide issue rather than a single‑tenant problem.

Microsoft has since patched the vulnerability, but the incident underscores the importance of limiting query permissions and monitoring for anomalous query patterns.

The exploit chain, dubbed CosmosEscape, demonstrates how a seemingly innocuous query language can be weaponized if sandbox boundaries are not rigorously enforced.

Wiz recommends that customers audit their Cosmos DB deployments for unused Gremlin endpoints and apply the latest security updates immediately.

While the patch mitigates the immediate risk, security experts advise continuous monitoring for signs of unauthorized query activity across all tenants.

This event serves as a reminder that even well‑established cloud services can harbor hidden pathways that, if discovered, can compromise multi‑tenant isolation at scale.

Azure Cosmos DB Vulnerability Threatened Multi‑Tenant Access

Microsoft Azure’s Cosmos DB, a globally distributed database service, re…

Microsoft Azure’s Cosmos DB, a globally distributed database service, re…

Microsoft Azure’s Cosmos DB, a globally distributed database service, recently disclosed a critical flaw that could let attackers bypass the Gremlin query sandbox and gain unrestricted access to customer data.

In a public statement, security firm Wiz outlined the vulnerability, codenamed CosmosEscape, highlighting how a crafted Gremlin query could trigger arbitrary code execution on the underlying host.

The attack chain begins with a specially crafted query against a Gremlin…

The attack chain begins with a specially crafted query against a Gremlin…

The attack chain begins with a specially crafted query against a Gremlin database that the attacker controls. Once the query runs, the sandbox is compromised, allowing the attacker to run native code.

With native code execution, the attacker can elevate privileges and read or write any database in the tenant, effectively breaking the isolation that Cosmos DB provides between customers.

Wiz noted that the flaw could affect all tenants that use the affected C…

Wiz noted that the flaw could affect all tenants that use the affected C…

Wiz noted that the flaw could affect all tenants that use the affected Cosmos DB version, making it a platform‑wide issue rather than a single‑tenant problem.

Microsoft has since patched the vulnerability, but the incident underscores the importance of limiting query permissions and monitoring for anomalous query patterns.

The exploit chain, dubbed CosmosEscape, demonstrates how a seemingly inn…

The exploit chain, dubbed CosmosEscape, demonstrates how a seemingly inn…

The exploit chain, dubbed CosmosEscape, demonstrates how a seemingly innocuous query language can be weaponized if sandbox boundaries are not rigorously enforced.

Wiz recommends that customers audit their Cosmos DB deployments for unused Gremlin endpoints and apply the latest security updates immediately.

While the patch mitigates the immediate risk, security experts advise co…

While the patch mitigates the immediate risk, security experts advise co…

While the patch mitigates the immediate risk, security experts advise continuous monitoring for signs of unauthorized query activity across all tenants.

This event serves as a reminder that even well‑established cloud services can harbor hidden pathways that, if discovered, can compromise multi‑tenant isolation at scale.