Overview
- Wiz privately reported the flaw in November 2025 and Microsoft blocked the vulnerable Gremlin entry point within 48 hours before completing a region-wide fix and removing the platform signing key in July 2026.
- Wiz publicly disclosed the chain on July 30 and plans to present the full technical exploit at Black Hat USA on August 6.
- Researchers say the exploit began with a Gremlin query in an attacker-controlled account that escaped the Gremlin sandbox, gained code execution on the multi-tenant DB Gateway, and exposed a platform secret dubbed the “Cosmos Master Key.”
- Possession of the Cosmos Master Key could let an attacker list accounts and request primary keys across APIs and regions, giving read and write control of targeted Cosmos DB accounts, though Wiz says it did not access customer data in its tests.
- Microsoft says the issue is fully addressed and that its investigation found no evidence of customer impact, but the exact exposure window and full log‑review scope were not disclosed and customers should review key access and account activity.