Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows

Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows

Listen to this article

0:00 —

Press play to start listening

A teen hacker found an authentication flaw in Microsoft’s Titan analytics service, where metadata indicated an estimated 17.3 trillion stored rows.

A 16-year-old using the alias Faav, who describes himself as a hacker and developer, found an authentication flaw in an internal Microsoft analytics service that could have allowed unauthorized SQL queries against an environment whose metadata indicated an estimated 17.3 trillion stored rows.

The flaw affected Titan, an internal analytics service whose web interface was restricted to Microsoft employees. However, its API remained reachable through an Azure Cloud Services host. The problem was that Titan checked several claims in authentication tokens but did not verify the tokens’ signatures, allowing an attacker to claim another user’s identity when accessing the service.

Unsigned Token Led to Administrator Access

Faav discovered the API on August 25, 2026, while participating in Microsoft’s bug bounty program. He initially used Antares, an AI-powered security research tool he developed, to investigate the service. The API’s /v2/Query endpoint accepted SQL queries and required authentication.

After testing the service’s JSON Web Token (JWT) checks, Faav found that changing token claims triggered different validation errors even when the signature remained unchanged. He then created an unsigned JWT using the alg:none header.

The unsigned token passed Titan’s tenant, audience and application checks. Faav then changed the token’s upn claim to admin. Titan treated it as a local username, mapped it to user ID 1 and assigned the account the service’s Admin role. This allowed Faav to execute SQL without valid Microsoft credentials.

A SQL query sent through Titan’s /v2/Query API and the resulting response, with sensitive information redacted. (Credit: Faav)

“Titan validated the contents of the JWT but never verified the signature, the most important part of any authentication check,” Faav wrote in his blog post.

Faav described the impact as hypothetical and said his testing was limited to metadata and bounded sample rows used to demonstrate the flaw. “I never touched any customer data or PII,” he added.

Metadata Revealed the Potential Scale

Faav first accessed Titan’s test database before finding its platform metadata database. Those records included employee account and email information, organizational records and details about the analytics environment.

He also accessed two one-row samples from a Bing analytics dataset. The samples contained search-related information, identifiers and high-level location data. Faav clarified that he did not identify individuals, correlate their activity or build profiles from the samples.

He then tested 56 routing values recovered from an archived Titan configuration and found 30 still active. Those routes connected to 17 analytics databases containing 9,863 unique table names. The database metadata indicated an estimated 17,333,335,124,315 stored rows.

Faav stressed that the 17.3 trillion figure was a storage estimate based on metadata and included historical, duplicated and derived data.

Microsoft Locked Down the API

Faav reported the issue to Microsoft’s Security Response Center (MSRC) on September 5 under Case 144051. Microsoft locked down the affected API on September 9, and Faav received a $5,000 bug bounty on September 17.

In a formal statement, Microsoft acknowledged the finding, thanking Faav for the coordinated disclosure and helping the company harden its services:

“We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future.”

Expert’s Perspective

Ensar Seker, CISO at SOCRadar, told Hackread.com that the case shows how a missing signature check can undermine other authentication controls.

“Titan was validating information inside the JWT, such as the tenant, audience and application, but according to the researcher, it was not verifying the cryptographic signature. If an attacker can control the claims without proving who issued the token, those downstream checks provide very little protection.”

Seker also cautioned against interpreting the 17.3 trillion figure as confirmed data exposure.

“The 17.3 trillion figure also needs to be understood carefully. It represents an estimated number of database rows, not 17.3 trillion individuals or confirmed stolen records. There is currently no evidence presented that malicious actors exploited the vulnerability, and the researcher deliberately limited access during testing.”

He also commented on the role AI played in the research, stating, “The AI system handled repetitive discovery, enumeration and authentication testing over several days, while the decisive breakthrough came from the researcher questioning an assumption about how the application interpreted the user identity field.”

Seker recommended cryptographic verification of JWT signatures, rejection of unsigned tokens and independent assessment of externally reachable APIs, even when their associated applications appear protected by VPN or internal-access controls.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts