Is it me or was there a similar vulnerability reported a few years ago? Something about the attacker getting access to all platform's users' databases, though not sure if it was cosmos or something similar.
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id...
"This vulnerability could have allowed me to compromise every Entra ID tenant in the world (except probably those in national cloud deployments)."