Junglewise Threat Intelligence

CVE-2026-69857: Microsoft Azure Cosmos DB authorization bypass through user-controlled key

CVE-2026-69857 · Severity: high · CVSS 8.5 · Published 2026-09-03

Technologies: Microsoft Azure Cosmos DB. Vendors: Microsoft.

Executive brief

Azure Cosmos DB is a cloud database service used by organizations to store and manage data. An authenticated attacker can bypass authorization controls by manipulating user-controlled keys, potentially allowing them to impersonate other users or access data they should not have permission to retrieve, leading to unauthorized data access and integrity violations.

Technical details

The vulnerability is an authorization bypass in Azure Cosmos DB that stems from improper validation of user-controlled keys used in authentication or access control. An attacker with valid credentials can craft or modify these keys to circumvent authorization checks and perform spoofing attacks over the network. The flaw allows an authenticated user to escalate privileges or access data belonging to other users. The attack requires the attacker to already have some form of network access and valid credentials to the service, limiting the attack surface to authorized or previously compromised accounts.

Affected products

  • Microsoft Azure Cosmos DB

Timeline

  • 2026-09-03: disclosed

References

Related threats