Impact
Improper access control in Azure Cosmos DB permits an attacker without authorization to run arbitrary code remotely. The flaw is classified as CWE-284, indicating that untrusted input leads to unauthorized access controls. If exploited, the attacker could compromise confidentiality by reading or modifying data, integrity by altering records, and availability by causing denial of service or taking the system hostage.
Affected Systems
Microsoft Azure Cosmos DB is the affected product. The CVE does not specify particular versions, so all deployments of Cosmos DB may be impacted. Organizations using any Cosmos DB instance should assess whether their environment matches the vulnerability characteristics described.
Risk and Exploitability
The CVSS score of 10 signals critical severity, and the EPSS score is very low (< 1%); the vulnerability is not listed in KEV. The likely attack vector is over the network, inferred from the description that the flaw permits execution of arbitrary code remotely. Given the potential for remote code execution, the risk is high and the vulnerability should be treated with immediate urgency until an official patch is released.
OpenCVE Enrichment