Description
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Published: 2026-07-30
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Azure Cosmos DB permits an attacker without authorization to run arbitrary code remotely. The flaw is classified as CWE-284, indicating that untrusted input leads to unauthorized access controls. If exploited, the attacker could compromise confidentiality by reading or modifying data, integrity by altering records, and availability by causing denial of service or taking the system hostage.

Affected Systems

Microsoft Azure Cosmos DB is the affected product. The CVE does not specify particular versions, so all deployments of Cosmos DB may be impacted. Organizations using any Cosmos DB instance should assess whether their environment matches the vulnerability characteristics described.

Risk and Exploitability

The CVSS score of 10 signals critical severity, and the EPSS score is very low (< 1%); the vulnerability is not listed in KEV. The likely attack vector is over the network, inferred from the description that the flaw permits execution of arbitrary code remotely. Given the potential for remote code execution, the risk is high and the vulnerability should be treated with immediate urgency until an official patch is released.

Generated by OpenCVE AI on August 2, 2026 at 04:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure Cosmos DB security update once it becomes available
  • Restrict network access to Cosmos DB by configuring firewall rules and using private endpoints
  • Implement and enforce strict role‑based access control, and regularly audit IAM policies to ensure least privilege

Generated by OpenCVE AI on August 2, 2026 at 04:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Title Azure Cosmos DB Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft cosmos Db
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:cosmos_db:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft cosmos Db
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Cosmos Db Cosmos Db
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-19T16:31:42.910Z

Reserved: 2026-07-27T19:02:26.600Z

Link: CVE-2026-66803

cve-icon Vulnrichment

Updated: 2026-07-30T21:02:51.551Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T21:18:12.743

Modified: 2026-08-04T20:46:44.650

Link: CVE-2026-66803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:00:05Z

Weaknesses