A 16-year-old security researcher, known as Faav, uncovered a critical authentication flaw in Microsoft's internal Titan analytics service that allowed him to bypass login token verification and obtain administrator access. The vulnerability exposed an estimated 17.3 trillion rows across 17 connected databases containing employee records and Bing search analytics.
Faav developed Antares, an automated bug-hunting tool, to identify the weakness. After Antares spent ten days probing Titan's login checks, Faav completed the exploit. He said, "Antares wouldn't have gotten here alone, and neither would I. Its persistence, plus one human hunch, is what made this find possible."
The Titan service's web interface required a Microsoft VPN, but Antares located a separate API endpoint with public documentation. A `/v2/Query` route accepted raw SQL commands and required an authorization header.
Faav began with a token from his external Entra test tenant. Titan rejected it with a tenant error. He modified the token's tenant to Microsoft's, triggering an audience error. Further adjustments to the audience and application ID led to a user lookup stage.
During this process, Faav discovered that Titan accepted modified token payloads while keeping the signature identical—a sign the system was not verifying the token's cryptographic signature. He said, "The payload kept changing while the signature stayed exactly the same, and Titan kept accepting the new claims, like a bouncer checking the name on every ID but never looking at the photo. That was the first big clue it wasn't verifying signatures."
Faav then crafted a token with the algorithm field set to "none" and an empty signature. This token bypassed initial checks and reached the user lookup stage. Antares spent days testing various email-style addresses in the token's `upn` field.
On Sept. 5, Faav manually changed the `upn` value to "admin." Titan processed this as a local username, matching it to user ID 1, which held the administrator role. Faav gained full administrator access and executed SQL queries against the service's databases.
Faav's access revealed the Titan platform's metadata database held approximately 25,000 account and email entries, 17,990 employee email records and 15,001 employee organization records. The data included job titles, departments and management hierarchy for staff associated with Titan. He suggested the information could have been used for targeted social engineering, though he did not pursue such actions.
Faav also accessed a Bing analytics source and extracted two one-row samples from its latest partition, demonstrating access to sensitive operational data. He identified 9,863 unique table names across the 17 connected analytics databases.
The Microsoft Security Response Center addressed the vulnerability after Faav's disclosure and awarded him a $5,000 bug bounty. Microsoft characterized the 17.3 trillion row count primarily as a theoretical storage estimate encompassing historical or duplicated metadata rather than directly exposed customer personally identifiable information.


