Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Azure Cosmos Db
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-69857 1 Microsoft 1 Azure Cosmos Db 2026-09-09 N/A 8.5 HIGH
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
CVE-2026-66803 1 Microsoft 1 Azure Cosmos Db 2026-08-04 N/A 10.0 CRITICAL
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2025-64675 1 Microsoft 1 Azure Cosmos Db 2026-06-17 N/A 8.3 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.