Description
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-17
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

Improper neutralization of special elements in output that a downstream component consumes creates an injection flaw in Azure Cosmos DB. When successfully triggered, this flaw lets an attacker who already has authorized access gain elevated permissions within the network, potentially moving from a limited scope to broader administrative control. The weakness is an input‑validation issue that allows malicious data to influence downstream processing.

Affected Systems

Microsoft Azure Cosmos DB is affected. No specific version information is disclosed, meaning all deployments of Azure Cosmos DB may be vulnerable until security updates are applied.

Risk and Exploitability

The CVSS score of 9.6 marks the vulnerability as critical. The EPSS score of less than 1% indicates that, as of now, exploitation likelihood is low, yet the potential impact remains severe. The flaw is not listed in CISA’s KEV catalog. The attacker must already possess authorized access to leverage the injection, suggesting an internal or lateral attack vector, but the escalation could compromise confidentiality, integrity, and availability across the network.

Generated by OpenCVE AI on September 19, 2026 at 00:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Azure Cosmos DB update or patch released by Microsoft; consult the Microsoft Security Response Center for the specific fix.
  • If a patch cannot be deployed immediately, isolate the Cosmos DB instance with firewall rules or network security groups to restrict access to trusted networks.
  • Enforce strict input validation and output encoding on data that flows into downstream components; use whitelisting to reject unexpected characters or structures.
  • Monitor audit logs for anomalous privilege escalation or injection attempts and configure alerts to notify security staff when suspicious activity is detected.

Generated by OpenCVE AI on September 19, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft azure Cosmos Db
CPEs cpe:2.3:a:microsoft:azure_cosmos_db:-:*:*:*:*:*:*:*
Vendors & Products Microsoft azure Cosmos Db

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Title Azure Cosmos DB Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft cosmos Db
Weaknesses CWE-74
CPEs cpe:2.3:a:microsoft:cosmos_db:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft cosmos Db
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Cosmos Db Cosmos Db
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:12:11.395Z

Reserved: 2026-09-08T23:57:53.797Z

Link: CVE-2026-87701

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:32.675Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T23:18:53.623

Modified: 2026-09-29T18:52:30.420

Link: CVE-2026-87701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:45:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')