News

Teen Forges Microsoft Titan Admin Access With Unsigned JWT, Reaching 17 Trillion Rows

A 16-year-old researcher forged admin access to Microsoft's internal Titan analytics platform because it never checked token signatures, then reported it and earned a $5,000 bounty.

Teen Forges Microsoft Titan Admin Access With Unsigned JWT, Reaching 17 Trillion Rows

A 16-year-old became an administrator of one of Microsoft's internal analytics platforms by handing it a login token with no signature at all. The platform, called Titan, accepted it.

The researcher, who goes by Faav, found that Titan did not verify JWT signatures. With forged admin access he could run SQL across 17 databases holding an estimated 17.3 trillion rows, Help Net Security reports. That figure comes from storage metadata and includes historical, duplicated and derived data, so it is a measure of scale, not a count of people.

How the door opened

Titan's user interface sits behind a VPN. Its API did not. Antares, an AI bug-hunting orchestrator Faav built, turned up public API documentation showing a /v2/Query endpoint that accepted raw SQL.

The token trick was almost embarrassingly simple. Faav sent a JWT with the algorithm set to "none" and an empty signature, and it passed. Setting the upn field to "admin" matched user ID 1, named Admin, on September 5.

From there, according to Tom's Hardware, he could see about 25,000 account and email entries, roughly 17,990 employee emails, and about 15,001 employee organization records with titles, departments and reporting lines for staff tied to Titan.

Bing data within reach

He also reached a Bing analytics source. Two one-row samples showed search terms, identifiers and location. Because the same MUID identifiers appeared across datasets, linking records together looked plausible, though Faav did not build any profiles. He says he never touched customer data or personal information.

He reported the flaw to the Microsoft Security Response Center on September 5. Microsoft locked Titan down by September 9 and paid a $5,000 bounty on September 17, thanking him for coordinated disclosure. Faav says Microsoft's editorial control cut sections and figures from his write-up before it went public.

It is another reminder that Microsoft's identity plumbing keeps producing basic token bugs, months after the Entra ID flaw CVE-2026-69836. Titan's lock only mattered to people using the front door. The API behind it never asked who was knocking.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free