· via Hacker News – Front Page (native)
Unsigned admin token opened Microsoft's Titan analytics to 17 trillion rows
A missing JWT signature check in Microsoft's internal Titan analytics let a researcher forge an admin token and query an estimated 17.3 trillion rows. The flaw was reported under Microsoft's bug bounty program.

An internal Microsoft analytics service never verified the signature on login tokens, a flaw that could have exposed an estimated 17.3 trillion stored rows across a wide range of Microsoft datasets, according to a disclosure write-up by security researcher Faav that surfaced on the Hacker News front page. By forging an unsigned token that claimed an administrator identity, the researcher was able to run unauthorized SQL queries against the service without holding any real credentials.
Finding Titan
The researcher, who says in the post that they are 16, was running a personal AI-driven reconnaissance tool called Antares when it flagged a service named Titan on August 25, 2026. Titan's web interface sits behind a VPN wall for Microsoft employees, but a separate API endpoint, hosted on Azure Cloud Services and described in a publicly readable Swagger file, was reachable. The documentation listed four routes, and the one that accepted raw SQL, /v2/Query, stood out from the other three in how its authentication was specified.
With no example table names given, the researcher pulled 2023 archives of Titan's login and privacy pages from the Wayback Machine and recovered 56 table definitions from an archived configuration, including a table called TestData.
A token that was never checked
The API rejected unauthenticated requests, so attention shifted to how Titan validated JWTs. Over ten days of probing, the service rejected tokens for the wrong tenant, then the wrong audience, then an unapproved application ID — but it kept accepting edited payloads while the signature stayed exactly the same. Titan was inspecting the claims inside each token but never confirming the token itself was genuine.
The researcher then submitted a synthetic JWT whose header declared the algorithm "none" and whose signature section was left empty. Titan accepted it. The last barrier was a user lookup: the AI models assisting the hunt kept guessing email-formatted identities, since that is what a UPN normally looks like, and none of them worked. Shortly after 1 a.m. on September 5, the researcher reasoned that the backend might be using the upn claim as a local application username rather than an Entra identity, and set its value to admin. That resolved to local user ID 1, which held the Admin role, and the query executed.
What was reachable
From there, a SHOW DATABASES query exposed Titan's platform metadata database. According to the write-up, it contained roughly 25,000 account and email records, 17,990 employee email records, 15,001 employee organization records, 355 database configurations, 20,979 virtual-dataset SQL definitions, and tens of thousands of dashboards, charts and dataset definitions. The employee data covered only a subset of Microsoft staff linked to Titan, but included job titles, departments and management hierarchy, information that could support targeted social engineering. A password field in the user table held a placeholder hash rather than real Microsoft credentials.
A separate Bing analytics source sat behind the same interface. The researcher validated access with a bounded one-row sample, and says the 17.3 trillion-row estimate rests only on table descriptions, metadata and such bounded samples. The stated impact is hypothetical: no customer data or personal information was accessed, and the flaw was reported rather than exploited.
Disclosure, with an asterisk
In a statement included in the post, Microsoft thanked the researcher, said the coordinated disclosure helped it harden its services, and said it looks forward to continued collaboration under its bug bounty program. The write-up also carries a transparency note: Microsoft had editorial control over the published post, cutting sections and figures and reshaping how the impact is described before publication — a reminder that vendor-approved disclosures may not show the full picture of what was found.
Why it matters
The technical failure is old and well understood: accepting an unsigned token defeats the entire purpose of bearer authentication, and this class of bypass has been documented for years. What makes the incident notable is the blast radius. Internal analytics platforms are aggregation points by design, so one weak check in one service became a potential doorway into datasets across the company, measured in trillions of rows, plus employee details useful for follow-on attacks.
It is also a data point in the debate over AI-assisted security research. Antares, running Codex and Claude models, found the service and methodically mapped its validation logic, but stalled at the final step because admin is not a valid UPN. The breakthrough came from a human questioning what the backend actually did with the claim. Effective bug hunting today looks like both: machines for persistence and coverage, people for the leap.
- #security
- #microsoft
- #azure
- #jwt
- #bug-bounty