Junglewise Threat Intelligence

CVE-2026-87701: Microsoft Azure Cosmos DB injection privilege escalation

CVE-2026-87701 · Severity: critical · CVSS 9.6 · Published 2026-09-17

Technologies: Microsoft Azure Cosmos DB. Vendors: Microsoft.

Executive brief

Azure Cosmos DB is a managed database service used by enterprises to store and query application data. An authorized attacker can exploit an injection vulnerability to escalate their privileges and gain unauthorized access to data or administrative functions, potentially compromising the confidentiality and integrity of customer information and operations.

Technical details

This vulnerability is an improper neutralization of special elements in output (injection) vulnerability in Azure Cosmos DB. An authorized attacker can exploit the flaw over the network to elevate their privileges. The root cause involves insufficient input validation or sanitization of special characters in output used by a downstream component, allowing an attacker to inject malicious commands or queries. The attack requires prior authentication to the service. Exploitation can result in privilege escalation, potentially allowing an attacker to perform unauthorized administrative operations. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Azure Cosmos DB

Timeline

  • 2026-09-17: disclosed

References

Related threats