Junglewise Threat Intelligence

CVE-2026-24304: Microsoft Azure Cosmos DB improper access control remote code execution

CVE-2026-24304 · Severity: critical · CVSS 10 · Published 2026-01-23

Executive brief

A critical vulnerability has been identified in Microsoft Azure Cosmos DB, a widely used cloud database service. This flaw allows an unauthorized attacker to gain control over the database environment and execute malicious code remotely over the network. An exploit could lead to a total compromise of customer data, service disruption, and unauthorized access to the broader cloud infrastructure. As this is a managed service, Microsoft typically handles the underlying infrastructure updates, but organizations should verify their security configurations.

Technical details

A critical vulnerability (CWE-284) exists in Azure Cosmos DB due to improper access control mechanisms. The flaw allows an unauthenticated attacker with network access to the service to bypass security restrictions and achieve remote code execution (RCE). The vulnerability is characterized by a high impact on confidentiality, integrity, and availability, with a CVSS score of 10.0 due to the lack of required privileges and the potential for scope change. While the initial report mentioned Azure Resource Manager, the latest vendor updates confirm the primary impact is within the Cosmos DB service. As a cloud-hosted service, remediation is primarily managed by the vendor, though users should monitor for related configuration advisories from Microsoft.

Affected products

  • Microsoft Azure Cosmos DB All versions

Timeline

  • 2026-01-22: disclosed: Initial disclosure by Microsoft Corporation
  • 2026-01-23: advisory: NVD publication date
  • 2026-07-30: other: Major update to CVE description and product scope from Resource Manager to Cosmos DB

References

Related threats