Azure Cosmos DB Spoofing Vulnerability
Summary
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. Published in September 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Why it matters
Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates. EPSS percentile: 35%.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-69857. Confirm whether Azure Cosmos DB is deployed, then apply the current security update or documented mitigation. CVSS score: 8.5. EPSS probability: 0.4%; percentile: 35%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.