Executive brief
Azure Cosmos DB is a cloud database service used by organizations to store and manage data. An authenticated attacker can bypass authorization controls by manipulating user-controlled keys, potentially allowing them to impersonate other users or access data they should not have permission to retrieve, leading to unauthorized data access and integrity violations.
Technical details
The vulnerability is an authorization bypass in Azure Cosmos DB that stems from improper validation of user-controlled keys used in authentication or access control. An attacker with valid credentials can craft or modify these keys to circumvent authorization checks and perform spoofing attacks over the network. The flaw allows an authenticated user to escalate privileges or access data belonging to other users. The attack requires the attacker to already have some form of network access and valid credentials to the service, limiting the attack surface to authorized or previously compromised accounts.
Affected products
- Microsoft Azure Cosmos DB
Timeline
- 2026-09-03: disclosed