CVE-2026-87701: Azure Cosmos DB Elevation of Privilege Vulnerability
Azure Cosmos DB Elevation of Privilege Vulnerability
Other sources
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access Azure Cosmos DB and be able to reach the affected service over a network. The provided data does not indicate that unauthenticated attackers can exploit it.
Does exploitation require user interaction or complex conditions?
No user interaction is required, and the attack complexity is rated low. The attacker does need low-level privileges before exploiting the issue.
What is the likely impact if exploitation succeeds?
Successful exploitation can allow privilege elevation, with high confidentiality and integrity impact. The scope is changed, meaning effects may extend beyond the initially authorized security scope.