CVE-2026-87701

Summary

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftAzure Cosmos DB-affected

Weaknesses

  • CWE-74: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

References