Cosmos DB account access is key-based by default: the account's primary key grants full read and write to every database and container, and is handed out by a control-plane call to anyone with Microsoft.DocumentDB/databaseAccounts/listKeys/action. There are also read-only keys, scoped resource tokens, and a data-plane RBAC model, but the primary key is the prize because it bypasses all of them.
Listing the keys#
az cosmosdb keys list --name <acct> -g <rg> --type keys
az cosmosdb keys list --name <acct> -g <rg> --type read-only-keys
# connection strings (key embedded)
az cosmosdb keys list --name <acct> -g <rg> --type connection-strings
Reading documents#
# with the key, query through the SQL (core) API endpoint
az cosmosdb sql container query --account-name <acct> -g <rg> \
-d <db> -c <container> --query-text "SELECT * FROM c"
Exploitation notes#
listKeysis a control-plane action, so a principal with Contributor or a custom role carrying it gets full data access without any data-plane role assignment.- Keys are static and rarely rotated, so a recovered primary key is durable access; it also appears in app settings and Automation assets, so check app settings first.
- Regenerate-and-steal is possible but noisy and breaks the application; prefer reading the existing key.
Tools#
- az cli (
az cosmosdb keys list,az cosmosdb sql container query). - MicroBurst: surfaces Cosmos DB keys during subscription enumeration.