InfoQ
Read post

Wiz Discloses CosmosEscape, and Practitioners Debate What Customers Could Have Done

Wiz Research disclosed CosmosEscape, a vulnerability chain in Azure Cosmos DB where a crafted Gremlin query escaped the sandbox via .NET reflection, achieving code execution on the DB Gateway and exposing a platform-wide master key granting read/write access to every database on the service. Microsoft blocked the entry point within two days of the November 2025 report but required until July 2026 to fully rearchitect the credential model. The blast radius included Microsoft's own backends like Teams and Copilot. Community debate centered on three themes: the shared responsibility model (customers had no mitigation available), the legitimacy of the six-month remediation timeline given the scale of rearchitecting a live multi-tenant credential system, and concentration risk in hyperscaler environments. Notable gaps in the public record include no CVE, no CVSS score, no MSRC advisory, and no defined exposure window, leaving the assurance of 'no customer impact' without a clear denominator. The full chain is scheduled for Black Hat USA.

    #security#multi-tenancy#azure-cosmos-db
Yesterday•5m read time•From infoq.com
Post cover image
InfoQ's image
InfoQ

InfoQ is a leading online platform for software developers, architects, and technical leaders, provi...

1.4K Followers

•

6.2K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard