CRITICAL: Azure Cosmos DB CVE-2026-66803 Exposed a Platform-Wide Master Key
Microsoft has disclosed CVE-2026-66803, a CVSS 10.0 improper access control flaw in Azure Cosmos DB that let researchers escape the Gremlin query sandbox and reach a platform wide signing key capable of retrieving the primary key for any Cosmos DB account on the service. Microsoft says no customer data was accessed and no customer action is required, but the finding is a hard lesson in cloud key hygiene and blast radius.