CVE-2026-69857: Azure Cosmos DB Spoofing Vulnerability
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access Azure Cosmos DB and be able to reach the affected service over a network. The available information does not indicate that unauthenticated attackers can exploit it.
What capabilities does exploitation provide?
Successful exploitation allows spoofing through an authorization bypass involving a user-controlled key. The supplied severity vector indicates potential impact to confidentiality, integrity, and availability, with scope changed.
Does exploitation require user interaction or a simple attack path?
No user interaction is required. However, the attack complexity is rated high, indicating exploitation depends on conditions beyond simply sending a basic network request.
Is a default Azure Cosmos DB deployment affected?
The available information identifies Microsoft Azure Cosmos DB as affected but does not state which configurations, deployment modes, or versions are vulnerable. It also does not provide a workaround or mitigation for environments that cannot be patched immediately.