• Sources: Wiz Research, discussion
  • Summary: Wiz Research describes an escape from the sandbox that runs Gremlin graph queries in Azure Cosmos DB. The escape reached a platform-wide signing key held by a shared gateway, which could retrieve the primary key of any Cosmos DB account across tenants, regions, and API flavors, including databases behind Microsoft Entra ID, Teams, and Copilot. Microsoft shipped a hot fix on 2025-11-22 and completed the architectural fix in July 2026. Microsoft states there is no evidence of exploitation outside the research and that no customer action is required.
  • Why it matters: A query language that compiles tenant input to host code is an isolation boundary, and a shared gateway holding a cross-tenant signing key turns one sandbox escape into access to every account on the service.

send feedback on this story