Microsoft Cosmos DB Gremlin API Vulnerability Exposes Master Key, Potential Full Account Takeover
What Happened — Researchers at Wiz disclosed a flaw dubbed CosmosEscape in Azure’s Gremlin API that unintentionally exposed the master key for any Cosmos DB account. The vulnerability could let an attacker authenticate as the account owner and gain unrestricted read/write access. Microsoft has issued a patch; no customer data loss has been reported.
Why It Matters for Compliance & Audit Readiness
- The flaw bypasses the very controls SOC 2 CC6.1 (Logical Access) expects you to enforce, highlighting the need for continuous key‑management monitoring.
- Demonstrates why evidence of key‑rotation, privileged‑access reviews, and automated alerting are essential audit artifacts.
- Aligns directly with Verisq’s SOC 2 Access Controls capability, which helps you capture and retain the logs and policy attestations required to prove robust access‑control hygiene.
Who Is Affected
- Cloud‑infrastructure providers and SaaS platforms that rely on Azure Cosmos DB (e.g., fintech, health‑tech, e‑commerce).
Recommended Actions
- Immediately verify that the Microsoft patch is applied to all Cosmos DB instances.
- Conduct a rapid key‑rotation for any Cosmos DB master keys and document the process.
- Map the incident to SOC 2 CC6.1 and CC7.2 (Change Management) controls, collect evidence of remediation, and update your continuous‑compliance dashboard.
Source: HackRead – Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
Technical Notes
- Attack vector: Exploitation of a code flaw in the Gremlin API that leaked the master key.
- CVE: None assigned yet; disclosed as a zero‑day by Wiz.
- Data at risk: Full read/write access to all data stored in the affected Cosmos DB accounts.