Impact
Improper neutralization of special elements in output that a downstream component consumes creates an injection flaw in Azure Cosmos DB. When successfully triggered, this flaw lets an attacker who already has authorized access gain elevated permissions within the network, potentially moving from a limited scope to broader administrative control. The weakness is an input‑validation issue that allows malicious data to influence downstream processing.
Affected Systems
Microsoft Azure Cosmos DB is affected. No specific version information is disclosed, meaning all deployments of Azure Cosmos DB may be vulnerable until security updates are applied.
Risk and Exploitability
The CVSS score of 9.6 marks the vulnerability as critical. The EPSS score of less than 1% indicates that, as of now, exploitation likelihood is low, yet the potential impact remains severe. The flaw is not listed in CISA’s KEV catalog. The attacker must already possess authorized access to leverage the injection, suggesting an internal or lateral attack vector, but the escalation could compromise confidentiality, integrity, and availability across the network.
OpenCVE Enrichment