ZeroHour

CVE-2026-87701

mass

Injection-Based Privilege Elevation in Azure Cosmos DB

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

Azure Cosmos DB contains an improper neutralization flaw (CWE-74) in which special elements in attacker-controlled input are passed unneutralized into output consumed by a downstream component, enabling an injection attack. The flaw is triggered over the network by an attacker who already holds a low-privilege, authorized position (such as a legitimate tenant or data-plane account), with no user interaction required. Because the CVSS scope is 'changed', successful exploitation crosses a security boundary, and the attacker gains elevated privileges with high confidentiality and integrity impact (no availability impact). All customers using the managed Azure Cosmos DB service are potentially affected, since fixes must be delivered through Microsoft's service updates. As of this writing, the flaw is not in CISA's KEV catalog and no public proof-of-concept or confirmed in-the-wild exploitation is known.

What to do: Monitor Microsoft's advisory and Azure Service Health and ensure your Cosmos DB accounts receive the service-side fix, which is applied by Microsoft rather than by customer patching. In the meantime, apply least privilege to Cosmos DB data-plane and control-plane RBAC roles, audit accounts or integrations that submit user-controlled content into Cosmos DB, and watch logs for anomalous cross-resource or cross-tenant access patterns.

Affected
Microsoft Azure Cosmos DBManaged cloud service (all customer-facing environments; no specific version range disclosed)
Estimated exposure
masslikely on the order of hundreds of thousands to 1M+ Azure tenants/accounts (exact counts unpublished) — Azure Cosmos DB is a flagship managed NoSQL service consumed by a large fraction of Azure's global enterprise customer base, so the plausibly affected population is the service's total tenant base, which Microsoft does not publish.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft patched a CVSS 10.0 missing-authentication privilege escalation flaw, CVE-2026-85889, in Azure AI Foundry, already fully mitigated server-side.

Microsoft fixed CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry (Microsoft Foundry) that allows unauthorized attackers to elevate privileges over a network, credited to researcher Rémy Marot. No exploitation in the wild was reported, and Microsoft says these cloud flaws are fully mitigated with no customer action required. The same effort covered CVE-2026-85885 (CVSS 9.9 command injection in Microsoft 365 Copilot), CVE-2026-85878 (CVSS 9.9 Azure Database for PostgreSQL), and CVE-2026-87701 (CVSS 9.6 Azure Cosmos DB). Out-of-band Windows 11 26H1 updates (KB5129194) also address local privilege escalation flaws CVE-2026-62721 and CVE-2026-85921.