{"id":8955,"date":"2026-07-31T12:53:47","date_gmt":"2026-07-31T12:53:47","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8955"},"modified":"2026-07-31T12:53:47","modified_gmt":"2026-07-31T12:53:47","slug":"microsoft-almost-gave-away-the-keys-to-everyones-azure-cosmos-dbs","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8955","title":{"rendered":"Microsoft almost gave away the keys to everyone\u2019s Azure Cosmos DBs"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases \u2014 both those of customers and Microsoft\u2019s own.<\/p>\n<p class=\"wp-block-paragraph\">Google subsidiary Wiz found a flaw in the database\u2019s Gremlin API, usually used for storing and managing property graph data.<\/p>\n<p class=\"wp-block-paragraph\">If bad actors had discovered it first, they could have exploited it to acquire what Wiz called the Cosmos Master Key, which would have enabled them to use the primary key of any Cosmos database, resulting in read and write access to any account. They would also have had access to a list of every database on the service, with identifiers such as subscription and tenant IDs.<\/p>\n<p class=\"wp-block-paragraph\">Azure Cosmos DB is a NoSQL database that underpins Microsoft\u2019s cloud services. It can be accessed through SDKs for framework such as Python, Node.js, Java, and .NET.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.wiz.io\/blog\/cosmosescape-taking-over-every-database-in-azure-cosmos-db\" target=\"_blank\" rel=\"noopener\">Wiz described how it discovered the vulnerability<\/a> in a blog post. It disclosed details of the flaw to Microsoft in November 2025.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft deployed a hot fix within two days, but it took another eight months to re-engineer the infrastructure, removing the Cosmos Master Key and introducing new guardrails to Cosmos DB to prevent similar attacks.<\/p>\n<p class=\"wp-block-paragraph\">It is not the first time Cosmos DB customers\u2019 primary keys have been under threat: In 2021, <a href=\"https:\/\/www.csoonline.com\/article\/571251\/cosmos-db-users-advised-to-regenerate-their-keys-following-serious-vulnerability.html\">Wiz found a flaw in data exploration tool Jupyter Notebook<\/a> that could be exploited to access the database keys and other secrets.<\/p>\n<p class=\"wp-block-paragraph\">\n<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases \u2014 both those of customers and Microsoft\u2019s own. Google subsidiary Wiz found a flaw in the database\u2019s Gremlin API, usually used for storing and managing property graph data. If bad [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8956,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8955"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8955"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8955\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8956"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}