CosmosEscape: Wiz Research Extracted a Single Key That Could Read and Write Every Azure Cosmos DB Database — Platform-Wide Master Key, Config Store Enumeration, Entra ID and Teams in Scope, No Customer Action Required
Wiz Research disclosed CosmosEscape — a chain of vulnerabilities in Azure Cosmos DB’s Gremlin API that allowed any attacker with a standard Cosmos DB account to escape the query sandbox via .NET reflection, execute code on Microsoft’s multi-tenant DB Gateway, and retrieve the Cosmos Master Key: a single platform-wide signing key giving full read/write access to every customer database across all tenants, regions, and API types. The Master Key also unlocked the Config Store — a queryable directory of every account on the platform, filterable by tenant ID. Microsoft’s internal Cosmos DB databases (Entra ID, Teams, Copilot) were in scope. No customer action required — server-side fix completed July 2026. Black Hat USA briefing: “One Key to Rule Them All.”
