16-Year-Old Researcher Discovers Microsoft Authentication Bug Exposing 17.3 Trillion Records
A teenage researcher found Microsoft Titan accepted unsigned JWTs, enabling admin SQL against huge internal analytics stores.
Researcher Faav, 16, found that Microsoft’s internal Titan analytics API checked JWT claims but did not cryptographically validate signatures. An unsigned token with an admin UPN was accepted, allowing privileged SQL against publicly reachable routes. Metadata from 17 ClickHouse databases implied about 17.3 trillion stored rows, a figure that includes replicas and derived data rather than confirmed customer records. Limited queries exposed roughly 25,000 account and email records and employee metadata; Microsoft restricted the endpoint on September 9, 2026, paid a $5,000 bounty, and no malicious exploitation is reported.
- Titan accepted unsigned JWTs, including alg:none, without verifying signatures.
- Forged admin claim let the researcher run privileged SQL on an exposed API.
- 17.3 trillion is an estimated row count, not exfiltrated customer records.
- Metadata views included about 25,000 accounts and nearly 18,000 employee emails.
- Microsoft locked the API four days after the Sept. 5 report and paid $5,000.
Full article686 words · extracted from gbhackers.com · click to collapse
A 16-year-old security researcher known as Faav discovered a significant authentication flaw in Microsoft’s internal Titan analytics service.
This vulnerability could have let an attacker impersonate an administrator and run unauthorized SQL queries. The researcher estimated that the vulnerable environment contained 17.3 trillion stored rows across 17 connected analytics databases.
However, this figure represents potentially reachable data. It does not indicate the number of records accessed, exfiltrated, or unique individuals involved.
The issue originated from improper validation of JSON Web Tokens (JWT). Titan reportedly checked token claims such as tenant ID, audience, application ID, and user identity.
However, it did not cryptographically validate the JWT signature. As a result, an attacker could modify identity claims while maintaining an invalid or absent signature, undermining the essential security control designed to prove that the token came from a trusted identity provider.
Microsoft Authentication Bug
The researcher used AI-assisted reconnaissance to identify Titan, an internal Microsoft analytics service with a web interface protected by a “VPN REQUIRED” page. However, a separate API endpoint was publicly accessible. It exposed a Swagger document listing several routes, including /v2/Query, which accepted raw SQL queries.
Initial unauthenticated requests returned HTTP 401 errors, indicating that the API required an authorization token. Faav then tested how the service handled JWT claims using a token from an external Entra tenant.
By modifying token fields, the researcher found that Titan processed changed tenant, audience, and application values, even though the original signature remained unchanged. This strongly suggested the service trusted claims without verifying their integrity.

The researcher then created a synthetic JWT using the alg: none header value, which denotes an unsigned token. Titan accepted this forged token after populating the required claims with the expected values.
Titan’s flawed authentication logic used the supplied `upn` claim to identify a local application user. Instead of requiring an email-formatted Entra identity, the backend accepted the value “admin,” which resolved to the platform’s local administrator account.
This allowed the researcher to execute SQL statements as a privileged user without valid Microsoft credentials. The main takeaway is that Titan’s multiple claim checks were ineffective because the application did not verify the token’s signature before trusting the claims.
The vulnerability did not result from stolen credentials, brute-force attacks, or an account compromise. It was an authentication-bypass condition caused by trusting attacker-controlled token content.
Faav tested 56 routing values recovered from archived Titan configuration data. Of these, 30 remained active and resolved through 24 configurations to 17 ClickHouse analytics databases containing 9,863 unique table names.
The researcher used database metadata, not bulk data extraction, to estimate a total of 17,333,335,124,315 stored rows. This estimate may include historical records, replicas, duplicate entries, and derived datasets; it should not be interpreted as 17.3 trillion customer records or 17.3 trillion affected individuals.
Limited access to metadata exposed approximately 25,000 account and email records, 17,990 employee email records, 15,001 employee organization records, dashboard definitions, dataset metadata, and database configurations.
The researcher also ran two one-row queries against Bing analytics data but stated that no customer personally identifiable information (PII) was accessed, no users were identified, and no cross-service correlation was performed.
Faav reported the issue to the Microsoft Security Response Center on September 5, 2026, under case number 144051. Microsoft restricted access to the exposed API endpoint on September 9 and awarded the researcher a $5,000 bounty on September 17.
Microsoft stated that the coordinated disclosure helped strengthen its services and better protect customers. No public evidence shows the flaw was exploited maliciously before it was fixed.
This incident highlights a fundamental security requirement for JWT: applications must reject unsigned tokens, enforce explicit signing algorithms, validate token signatures against trusted keys, and only then process claims related to the issuer, audience, tenant, and user identity.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.