Home / Jul 31, 2026 / Story
0
#9 The Hacker News general July 30, 2026 at 13:34 UTC

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

By [email protected] (The Hacker News)

AI Summary

Wiz researchers discovered and disclosed 'CosmosEscape,' a now-patched exploit chain in Azure Cosmos DB that began with a crafted Gremlin query and allowed sandbox escape to obtain a platform-wide key granting full read/write access to databases across customer tenants. The cross-tenant data exposure potential makes this a critical cloud security incident affecting Azure's multi-tenant isolation model.

Relevance score: 83.0/100

# More from July 31