🔴 Critical | Source: Microsoft Security Response Center
A vulnerability in Azure Cosmos DB allows an unauthenticated attacker to remotely execute arbitrary code over a network without requiring any user interaction or elevated privileges. The flaw stems from improper access control within the service. This is particularly serious given Cosmos DB’s widespread use as a managed database backend in enterprise and cloud-native applications.
Security Architect’s Take: Review all Cosmos DB instances for exposure to public or untrusted networks and apply any available Microsoft patches or mitigations immediately. Consider restricting Cosmos DB access to private endpoints and virtual network service endpoints while awaiting a full fix, and monitor for anomalous activity in Azure Monitor and Defender for Cloud.
Original advisory: CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability