Affected Systems
Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation. Products storing data in Cosmos DB (Teams, Copilot) were potentially accessible.
Exploitation Status
No active exploitation detected. Discovered by Wiz researchers in November 2025 through coordinated disclosure. Microsoft blocked vulnerable entry point within 48 hours; full fix completed July 2026. No CVE assigned. Full technical details to be presented at Black Hat USA August 6, 2026. Proof-of-concept demonstrated code execution and key retrieval but not published.
Business Impact
Critical cross-tenant data breach risk. Attacker with a valid Cosmos DB Gremlin account could escape sandbox via .NET reflection, execute code on multi-tenant gateway, retrieve platform-wide signing key (Cosmos Master Key), access regional Config Store directory, and obtain primary keys for any customer database across all tenants and regions. Primary keys grant full read/write control. Network isolation and private endpoints were bypassable. Microsoft investigation found no unauthorized access or customer data compromise. No customer action required per Microsoft. No CVSS score published.
Urgency
🟡 Within a week
Recommended Actions
- Review Azure Cosmos DB access logs from November 2025 through July 2026 for anomalous Gremlin query patterns, unexpected primary key usage, or cross-tenant access attempts
- Rotate all Azure Cosmos DB primary keys as a precautionary measure, prioritizing accounts containing sensitive data (Teams messages, Copilot conversation histories, PII)
- Audit Azure Activity Logs and Cosmos DB diagnostic logs for unauthorized account enumeration, Config Store access, or network configuration changes during the exposure window
- Verify that Azure Cosmos DB instances are running patched versions post-July 2026 and confirm Gremlin gateway components have been updated
- Monitor Wiz and Microsoft advisories for additional technical details following Black Hat USA presentation on August 6, 2026, and reassess risk posture accordingly
