Wiz Research revealed a significant vulnerability in Azure Cosmos DB's Gremlin API, known as CosmosEscape This article explores vulnerability azure cosmos. . Wiz capitalized on this loophole by developing file read, write, and arbitrary code execution capabilities, enabling remote code execution on the DB Gateway's multi-tenant Service Fabric component that handles customer queries.
Executing hostname on Cosmos DB (Source: Wiz.io) revealed a signing key for accessing any Cosmos DB account's primary key, granting full read/write access across various accounts, regions, and API types (SQL, MongoDB, Cassandra, Gremlin). The Wiz Blog analysis highlighted how chaining multi-tenant signing keys with administrative metadata endpoints resulted in a catastrophic blast radius effect throughout cloud infrastructure.
This risk is similar to recent authentication bypass vulnerabilities where overprivileged architectural keys can bypass perimeter controls, leading to cross-tenant risks that mirror the precision of CosmosEscape's Attack Chain (Image Source: Wiz.io). These infrastructure exposure vectors mirror risks observed in severe Microsoft zero-day flaws where underlying administrative roles bypass tenant boundary controls. Attack Lifecycle Stage Exploit Primitives & Mechanisms Technical Operational Impact Sandbox Escape Unrestricted .NET Reflection in Gremlin Engine Remote Code Execution on Multi-Tenant DB Gateway Credential Harvesting Extraction of the signing key for the global Cosmos DB Master Key Access to the Config Store Directory Full Read/Write Data Compromise Across All Regions and APIs Wiz reported CosmosEscape to Microsoft on November 20, 2025.












