Researchers say a vulnerability in Microsoft's Cosmos DB could have let an attacker escape the service's Gremlin query sandbox This article explores vulnerability microsoft cosmos. . The exploit chain began with a crafted query against a Gremlin database controlled by the attacker.

From there, code execution on a multi-tenant gateway exposed a platform-wide signing secret and a regional account directory. Microsoft blocked the vulnerable Gremlin entry point within 48 hours of the November 2025 report, according to Wiz, which codenamed the chain CosmosEscape. Wiz said Microsoft completed the longer-term fix across all regions in July 2026 and eliminated the platform- wide key.. Microsoft said its review found no unauthorized activity outside the researchers' testing. No customer data was accessed and no customer action is required, the company said.

The researchers said they will present the complete chain at a Black Hat USA briefing on August 6. They have not published whether the exploit required anything beyond that starting point. CosmosEscape is technically separate from the ChaosDB and CosMiss flaws disclosed in 2021 and 2022, which involved Cosmos DB's Jupyter Notebook feature.

The disclosure lists no CVE identifier or severity score. It does not say when the vulnerable engine and signing-key path entered production or what period Microsoft's log review covered. The duration of potential exposure remains unknown, although the known path has since been closed. It is not known when the vulnerability was discovered or how long it could have been exposed to the general public.

The vulnerability has not been identified as a potential security breach by the security team. It has been described as a "potential security breach" by the vulnerability team at Wiz, which has been working with Microsoft to fix the problem. The flaw has not yet been identified by the public as a security breach, but Wiz has said it is potentially accessible.