Executive brief
A critical security flaw has been identified in Microsoft Azure Cosmos DB, a widely used cloud database service. This vulnerability allows an unauthorized person to remotely execute malicious code over the network without needing any login credentials. An exploit could lead to a total compromise of the database environment, including the theft of sensitive customer data and the disruption of business operations.
Technical details
A vulnerability classified as improper access control (CWE-284) exists in Microsoft Azure Cosmos DB. The flaw allows an unauthenticated attacker to achieve remote code execution (RCE) via a network-based attack vector. According to the CVSS 3.1 score of 10.0, the attack has low complexity, requires no user interaction, and results in a 'Changed' scope, indicating the attacker can impact components beyond the database itself. Microsoft has acknowledged the issue, and users are advised to consult the Microsoft Security Response Center (MSRC) for mitigation and patching guidance.
Affected products
- Microsoft Azure Cosmos DB All versions
Timeline
- 2026-07-30: disclosed: Initial disclosure by Microsoft and NVD publication.