A serious security vulnerability, named CosmosEscape, was discovered in Microsoft Azure's Cosmos DB service, allowing attackers to potentially compromise all databases within the platform. The flaw could enable unauthorized access to primary keys of Cosmos DB accounts through the Gremlin API.
Wiz, the cybersecurity firm that reported the issue, revealed that the exploit could allow an attacker to list databases, filter them by organization IDs, and gain access through a platform-wide key referred to as the Cosmos Master Key. This security defect was reported to Microsoft in November 2025 and was patched swiftly, with a long-term fix implemented shortly after. Microsoft found no evidence of unauthorized access related to this vulnerability.