
Microsoft has said a vulnerability in Azure Cosmos DB has been fully addressed after cybersecurity researchers disclosed a flaw that could have allowed cross-tenant compromise of cloud customer databases. The issue, disclosed as CosmosEscape, affected Azure Cosmos DB’s Gremlin API path and could have enabled an attacker to escape the Gremlin query sandbox, obtain powerful service-level secrets and retrieve account keys for customer databases.
Wiz said the exploit chain began with a crafted query against a Gremlin database controlled by an attacker. From there, code execution on a multi-tenant gateway exposed a platform-wide signing secret and a regional account directory. The researchers said this could have allowed a malicious actor to locate target accounts and retrieve primary account keys. Microsoft documentation treats a Cosmos DB account primary key as granting full control over resources in the account, making the potential exposure significant for enterprises using Cosmos DB for application data, chatbots, recommendation systems and internal services.
Microsoft blocked the vulnerable Gremlin entry point within 48 hours of the November 2025 report and completed longer-term fixes across all regions in July 2026. The company said it found no evidence of customer impact, no customer data access and no unauthorised activity beyond the researchers’ testing. It also said no customer action is required. The disclosure did not list a CVE identifier or severity score at the time of publication.
The issue is important for enterprise cloud risk teams because Cosmos DB is used not only by external customers but also by Microsoft services. Wiz said databases supporting Microsoft Teams and Copilot were potentially reachable through the service-level weakness, although it did not report accessing their data. The vulnerability is separate from earlier Cosmos DB issues disclosed in 2021 and 2022, but it reinforces the operational challenge of securing multi-tenant cloud infrastructure where a flaw in a shared service layer can create broad exposure before it is patched.
For Indian enterprises, the case lands in a market where Azure is deeply embedded across banking, IT services, retail, manufacturing, GCCs, startups and public-sector digital systems. It also arrives as enterprises expand AI and automation workloads on cloud databases and managed services. The practical priority for security leaders is not emergency remediation, since Microsoft says the issue has been fixed and no customer action is required, but assurance: validating cloud exposure management, privileged key monitoring, tenant-level logging, third-party risk review and incident-response playbooks for managed-service vulnerabilities that sit outside the customer’s direct control.




