azure_cosmos_db vulnerabilities
CVEs whose affected-version data names the azure_cosmos_db package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-87701Critical· 9.6Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · Azure Cosmos DBEPSS 0.44%via NVD
CVE-2026-69857High· 8.5Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
▾ Twilightmicrosoft · azure_cosmos_dbEPSS 0.44%via NVD
CVE-2026-66803Critical· 10.0Azure Cosmos DB Remote Code Execution Vulnerability
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
▾ MidnightMicrosoft · Azure Cosmos DBEPSS 0.55%via CVEORG