Authorization Bypass Vulnerability in Azure Cosmos DB by Microsoft
CVE-2026-69857

8.5HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
3 September 2026

What is CVE-2026-69857?

A vulnerability in Azure Cosmos DB enables an authorized attacker to exploit user-controlled keys, thereby bypassing authentication mechanisms. This vulnerability can lead to spoofing attacks over the network, potentially compromising data integrity and security. Users of Azure Cosmos DB are encouraged to review their configurations and ensure that they are applying the latest security patches to mitigate this risk.

Affected Version(s)

Azure Cosmos DB -

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.