• PATCH AVAILABLE

CVE-2026-66803: pre-auth remote code execution in Microsoft Azure Cosmos DB

An unauthenticated attacker can execute code on Azure Cosmos DB over a network, enabling full compromise of the service and data, per CVE-2026-66803. The vulnerability affects the Azure Cosmos DB branch; vendor fixed versions are not listed in the supplied facts. The CVSS vector indicates no privileges or user interaction are required and the flaw can be exploited remotely, so an attacker needs only network access to a vulnerable Cosmos DB endpoint.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00901
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, unauthenticated code execution with a critical CVSS 10.0 rating—prioritise mitigation now by applying vendor updates or limiting network exposure to Cosmos DB endpoints.

What is CVE-2026-66803?

An unauthenticated attacker can execute code on Azure Cosmos DB over a network, enabling full compromise of the service and data, per CVE-2026-66803. The vulnerability affects the Azure Cosmos DB branch; vendor fixed versions are not listed in the supplied facts. The CVSS vector indicates no privileges or user interaction are required and the flaw can be exploited remotely, so an attacker needs only network access to a vulnerable Cosmos DB endpoint.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Microsoft Azure Cosmos DB are affected?

BRANCHAFFECTEDFIXED
Azure Cosmos DB-

Is CVE-2026-66803 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-66803

  1. Apply the vendor's security updates or guidance for Azure Cosmos DB as soon as they are available.
  2. Restrict network access to Cosmos DB endpoints (use virtual network rules, firewall, and least-privilege access).
  3. Increase monitoring and logging for Cosmos DB activity and alert on unusual or high-privilege operations.
  4. Rotate credentials, keys, and connection strings for Cosmos DB instances exposed before mitigations are applied.

Frequently asked questions

Is CVE-2026-66803 being actively exploited?

There are no public reports of active exploitation of CVE-2026-66803 as of 2026-09-29.

Which Azure Cosmos DB versions are affected by CVE-2026-66803?

The reported impact covers the Azure Cosmos DB branch; the supplied facts do not list specific affected or fixed versions.

Is there a patch for CVE-2026-66803?

A patch is indicated as available in the supplied facts, but fixed version numbers are not provided; follow Microsoft's guidance and apply their updates immediately.

Does CVE-2026-66803 require authentication?

No; the vulnerability is exploitable without authentication or user interaction, meaning an attacker with network access to the service can exploit it.

References