16-Year-Old Researcher's JWT Flaw in Microsoft's Titan Analytics Exposed Metadata Across an Estimated 17.3 Trillion Rows
A 16-year-old researcher found Microsoft's internal Titan analytics API accepted unsigned JWTs with algorithm 'none' and admin claims, enabling privileged SQL against 17 ClickHouse databases estimated at 17.3 trillion rows; Microsoft locked the endpoint on…
Researcher Faav, 16, found that Microsoft's internal Titan analytics service checked JWT claims but did not cryptographically verify signatures. An unsigned token with algorithm 'none,' an empty signature, and an admin identity was accepted, allowing privileged SQL queries against publicly reachable routes on 17 connected ClickHouse databases holding an estimated 17.3 trillion stored rows. All reports agree the 17.3 trillion figure is a row count including historical, duplicated, replica, and derived data, not confirmed customer records or unique people. GBHackers and Help Net Security report limited queries exposed roughly 25,000 account and email entries, 17,990 employee email records, 15,001 employee organization records, and two Bing search analytics samples with potential MUID correlation, while Cyber Security News states Faav did not access customer PII — a disagreement between sources, though the exposed data is described as platform metadata rather than exfiltrated customer records. Faav reported the flaw to MSRC on September 5, 2026; Microsoft locked the endpoint on September 9 and paid a $5,000 bounty on September 17. Help Net Security adds that the discovery was aided by Antares, an automated bug-hunting tool Faav built himself. No source reports evidence of malicious exploitation.
- Titan checked JWT claims but did not verify signatures, accepting an unsigned token with algorithm 'none,' an empty signature, and an admin UPN.
- The forged admin token allowed privileged SQL queries against 17 connected ClickHouse analytics databases.
- Metadata across the databases implied roughly 17.3 trillion stored rows, an estimate that includes historical, duplicated, replica, and derived data rather than confirmed customer records or unique people.
- Limited queries exposed about 25,000 account and email entries, 17,990 employee email records, 15,001 employee organization records, and two Bing search analytics samples with MUID correlation potential.
- Sources disagree on data exposure: Cyber Security News says Faav did not access customer PII, while GBHackers and Help Net Security describe exposed account, email, and employee metadata.
- Faav reported the flaw to MSRC on September 5, 2026; Microsoft locked the endpoint on September 9, 2026, four days later.
- Microsoft paid a $5,000 bounty, awarded on September 17, 2026 per Help Net Security.
- The discovery was aided by Antares, a self-built automated bug-hunting tool, per Help Net Security.
Coverage timelineoldest first · each row is one article
- · 4d ago16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records
Cyber Security News· 70
A teenage researcher found Microsoft Titan accepted unsigned JWTs, potentially reaching an estimated 17.3 trillion stored rows.
- · 2d ago16-Year-Old Researcher Discovers Microsoft Authentication Bug Exposing 17.3 Trillion Records
GBHackers· 64
A teenage researcher found Microsoft Titan accepted unsigned JWTs, enabling admin SQL against huge internal analytics stores.
- · 1d ago