Teen researcher uncovered flaw granting admin access to Microsoft’s Titan databases

← Back to the feed

Teen researcher uncovered flaw granting admin access to Microsoft’s Titan databases

The Register · 5 hours ago

A 16-year-old security researcher named Faav discovered a critical authentication vulnerability in Microsoft's Titan analytics service that allowed him to gain administrator access to internal databases containing an estimated 17.3 trillion rows of data. Working with an AI hackbot he built called Antares, Faav exploited a flaw in the service's Azure Cloud Services API that failed to verify the signature on login tokens, enabling him to submit unauthorised SQL queries without valid credentials. Microsoft acknowledged the vulnerability, patched the system, and awarded Faav a $5,000 bug bounty through its coordinated vulnerability disclosure programme.

The technical flaw centred on Microsoft's Titan platform using JSON Web Tokens (JWT) for authentication but failing to verify the token signatures—the most critical security component. After 10 days of testing starting 25 August, Faav discovered he could alter an unsigned token's user principal name from an email-formatted identity to "admin," which Titan then resolved to local user ID 1 with administrative privileges. This granted him access to platform metadata containing 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions, plus employee information including job titles, departments, and management hierarchies. Further investigation revealed 30 active routing values pointing to 17 connected analytics databases spanning 9,863 unique table names—all accessible due to the single missing authentication check.

  • 16-year-old bypassed JWT signature verification on Microsoft's internal analytics service
  • Gained admin access to databases with 17.3 trillion rows of sensitive data
  • Microsoft paid $5,000 bounty; vulnerability has been patched

Software

Read the full article at the source →

Originally published by The Register as “16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows”.