Improper Access Control in Azure Cosmos DB by Microsoft
CVE-2026-66803

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
30 July 2026

What is CVE-2026-66803?

This vulnerability in Azure Cosmos DB arises from insufficient access control mechanisms, which may lead to unauthorized code execution over a network. Attackers exploiting this flaw could potentially execute malicious code in a compromised environment, posing a significant risk to data integrity and confidentiality. It is crucial for users of Azure Cosmos DB to apply the recommended patches to mitigate this vulnerability and enhance their security posture. For more details, refer to the official vendor advisory.

Affected Version(s)

Azure Cosmos DB -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.