Wiz Discloses CosmosEscape, and Practitioners Debate What Customers Could Have Done
Microsoft took five months to revoke a master key after a sandbox escape. Practitioners are asking: what's your shared responsibility model worth?

Why it matters
A disclosed vulnerability in Azure Cosmos DB exposed the gap between blocking an attack vector and actually removing the blast radius. The debate among practitioners centers on who bears the cost of remediation — and whether Azure's security posture meets enterprise standards.
The key facts
9 to knowCosmosEscape: sandbox escape in Azure Cosmos DB Gremlin API
Vulnerability granted platform-wide read/write access to all databases
Microsoft blocked entry point within 2 days; key revocation took 5 months (until July 2026)
Disclosure by Wiz Research
Practitioner debate on shared responsibility model and rearchitecture costs
CosmosEscape vulnerability: sandbox escape in Azure Cosmos DB's Gremlin API
Attack chain reached platform-wide master key with read/write access to all databases
Microsoft blocked entry point within 2 days; revoked the key in July 2026 (5-month delay)
Practitioner debate focused on shared responsibility model and remediation costs
Go to the source
InfoQ AI/MLinfoq.com
Publisher excerpt: Wiz Research disclosed CosmosEscape, a chain that escaped Azure Cosmos DB's Gremlin sandbox and reached a platform-wide key granting read and write access to every database on the service. Microsoft blocked the entry point within two days but took until July 2026 to remove the key. Practitioners…
