← Back

Azure Cosmos Db

azure_cosmos_db

Vendor: Microsoft • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Azure Cosmos Db
Sep 9, 2026
Sep 3, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
1Microsoft
1Azure Cosmos Db
Aug 4, 2026
Jul 30, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
1Microsoft
1Azure Cosmos Db
Jun 17, 2026
Dec 19, 2025
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.