Utopia Tech
SecurityAI-assisted1 min read

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A critical vulnerability in Azure Cosmos DB, dubbed CosmosEscape by Wiz researchers, could have allowed attackers to escape the Gremlin query sandbox and gain unauthorized read/write access to databases across all customer tenants. The exploit chain began with a specially crafted query against an attacker-controlled Gremlin database, leading to code execution that could compromise the entire platf

UT

Utopia Tech

July 30, 2026 · 1 min read

Share

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content