OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-87701

CRITICAL · CVSS 9.6 EPSS 0.79%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Azure Cosmos DB is vulnerable due to improper handling of special elements in output, enabling an authorized attacker to perform injection attacks that can elevate their privileges over the network. This critical vulnerability, with a CVSS score of 9.6, poses a significant risk to data integrity and confidentiality. Organizations utilizing Azure Cosmos DB should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-87701
Severity
CRITICAL
CVSS
9.6
EPSS
0.79%

Original NVD Description

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)