AI analysis
Azure Cosmos DB contains an improper neutralization flaw (CWE-74) in which special elements in attacker-controlled input are passed unneutralized into output consumed by a downstream component, enabling an injection attack. The flaw is triggered over the network by an attacker who already holds a low-privilege, authorized position (such as a legitimate tenant or data-plane account), with no user interaction required. Because the CVSS scope is 'changed', successful exploitation crosses a security boundary, and the attacker gains elevated privileges with high confidentiality and integrity impact (no availability impact). All customers using the managed Azure Cosmos DB service are potentially affected, since fixes must be delivered through Microsoft's service updates. As of this writing, the flaw is not in CISA's KEV catalog and no public proof-of-concept or confirmed in-the-wild exploitation is known.
What to do: Monitor Microsoft's advisory and Azure Service Health and ensure your Cosmos DB accounts receive the service-side fix, which is applied by Microsoft rather than by customer patching. In the meantime, apply least privilege to Cosmos DB data-plane and control-plane RBAC roles, audit accounts or integrations that submit user-controlled content into Cosmos DB, and watch logs for anomalous cross-resource or cross-tenant access patterns.
Affected
| Microsoft Azure Cosmos DB | Managed cloud service (all customer-facing environments; no specific version range disclosed) |
Estimated exposure
masslikely on the order of hundreds of thousands to 1M+ Azure tenants/accounts (exact counts unpublished) — Azure Cosmos DB is a flagship managed NoSQL service consumed by a large fraction of Azure's global enterprise customer base, so the plausibly affected population is the service's total tenant base, which Microsoft does not publish.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.