Post #4276729
2026-07-31 11:27 UTC
Wiz's CosmosEscape reached one platform key in Azure Cosmos DB that could read and write any customer's database, across tenants.
Microsoft fixed it, no known impact.
Lesson: turn Cosmos key-based auth off where your API allows.
https://suriq.io/blog/azure-cosmos-db-cosmosescape-master-key
#CVE #CloudSecurity #infosec #cybersecurity
Replies (0)
No replies.