16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records
A teenage researcher found Microsoft Titan accepted unsigned JWTs, potentially reaching an estimated 17.3 trillion stored rows.
Sixteen-year-old researcher Faav reported an authentication flaw in Microsoft’s internal Titan analytics API. Titan checked JWT claims but did not verify signatures and accepted an unsigned token with algorithm “none” and user “admin,” allowing SQL queries. Counts across 17 ClickHouse databases produced an estimate of about 17.3 trillion stored rows, which Faav said likely included historical, duplicated, and derived data rather than unique people. Faav did not access customer PII, found no evidence of malicious exploitation, and Microsoft disabled the endpoint on September 9, 2026, later paying a $5,000 bounty.