Teen's Auth Flaw Opened Titan's Data Vault
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.
At 2 a.m. on a Saturday, most 16-year-olds are asleep. Faav was staring at a number: 17,333,335,124,315. It was the row count he had just accessed through an authentication flaw in Microsoft's internal Titan analytics service. With no valid credentials, he had become a Titan administrator, able to run SQL queries across databases containing an estimated 17.3 trillion rows. Microsoft has since locked down the API and paid him a $5,000 bug bounty.
A Boy and His AI Hackbot
Faav's research began on August 25 when an AI hackbot he built, called Antares, found Titan's public API. Titan is an internal analytics platform, and Microsoft restricts access via its web interface to employees. For the next 10 days, the human and bot tested the service's JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs).
They eventually found an unsigned token that could reach Titan's local user lookup, but not a UPN that Titan recognized. Early on September 5, Faav changed the unsigned token's UPN from an email-formatted identity to admin. Titan recognized it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL.
The core issue, as Faav described it in his blog: Titan validated the contents of the JWT — tenant, audience, app ID, user — but never verified the signature, the most important part of any authentication check. He compared the authentication checks to "a hotel where every door had a working keycard reader, but any keycard unlocked any room." Despite all the access-control logic existing in the app, the one missing piece made it all pointless.
What the Metadata Revealed
Access to Titan's platform metadata database allowed Faav to query application tables directly. According to his blog, the metadata contained:
- About 25,000 account and email records.
- 17,990 employee email records.
- 15,001 employee organization records.
- 355 database configurations.
- 20,979 virtual-dataset SQL definitions.
- 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions.
Titan's user and usage directory exposed employee job titles, departments, and management hierarchy, which Faav noted could be useful for social-engineering attacks — "though I never tested or demonstrated that," he added. He also found a Bing analytics sample and tested two rows that contained search info, identifiers, and high-level location information, such as country- or state-level details. Faav said the location values did not contain precise user locations.
The 17.3 Trillion-Row Jackpot
Then came the jackpot. Faav tested 56 routing values from an archived configuration and discovered 30 were still active. "Each routing value pointed to a backend configuration, and each configuration contained one or more databases, so the 30 live values resolved through 24 configurations to 17 connected analytics databases spanning 9,863 unique table names," he wrote.
The total came to about 17.3 trillion rows, which Faav says is a storage estimate derived from metadata and likely includes historical, duplicated, and derived data. "But quite the high number nonetheless," he wrote. The exact figure he first saw was 17,333,335,124,315.
Responsible Disclosure and Microsoft's Response
Between September 6 and September 8, Microsoft asked the teen to stop testing and requested his IP address to confirm no nefarious activity beyond the bug bounty research. A day later, Redmond locked down the endpoint and told Faav the "report prompted immediate investigation and remediation to address the remaining exposure." Microsoft awarded the bug hunter $5,000 for his work on September 17.
Faav also notes that he rewrote his blog post at Microsoft's request, cut sections and numbers, and reworded the impact prior to publication. In a statement provided to Faav for his blog, Microsoft said:
"We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future."
— Microsoft, in a statement provided to Faav for his blog
The Takeaway for Developers
Faav's blog includes a direct lesson: "If you're a developer (or coding agent) reading this, the most important takeaway from this post is to make sure you verify signatures above all else when building auth." The flaw hinged on a single missing check — the JWT signature — while all other access-control logic functioned as intended.
The 10-day testing period involved repeated authentication errors. The breakthrough came after Faav returned to the problem after finishing Friday's schoolwork and finally managed to execute SQL as a Titan admin after 1 AM Saturday. "It was 2 AM," Faav said in his blog. "I wanted to yell, or at least say something out loud, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again."
Microsoft has not publicly commented beyond the statement provided to Faav. The company locked down the API, and the bug bounty was paid on September 17. Faav's research underscores the importance of signature verification in authentication systems, especially as AI-assisted tools like Antares become more accessible to independent researchers.
Implications for the Industry
The incident highlights a persistent class of vulnerability: authentication mechanisms that validate token contents but skip signature checks. For enterprises running internal analytics platforms, the lesson is that access controls are only as strong as their weakest link. Microsoft's swift remediation and bounty payment suggest its bug bounty program is functioning as intended, but the fact that a 16-year-old with an AI bot could reach admin-level SQL execution raises questions about how many similar gaps exist elsewhere.
For defenders, the case reinforces the value of coordinated disclosure and the role of independent researchers — even very young ones — in finding critical flaws. For attackers, the exposed metadata (employee hierarchy, email records, dashboard definitions) could serve as reconnaissance material, though Faav did not demonstrate exploitation beyond access. The episode also illustrates the growing use of AI in security research, with Antares automating the discovery of Titan's public API. As AI tools become more capable, the barrier to entry for finding such flaws may continue to drop, making robust authentication checks — starting with signature verification — more critical than ever.
Sources
- The Register Original source
Continue Reading
Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.
AI-Discovered Flaws Skew Toward RCE
Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.
Google: AI Is Rewriting Bug Economics
GTIG data shows vulnerability disclosures doubled in 2026 while exploitation shifted toward n-days, with AI-discovered flaws carrying a riskier profile.