> 16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
[DATE: 30/09/2026 18:29]
[LANGUAGE: EN]
A 16-year-old security researcher named Faav found an authentication flaw in Microsoft’s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows. Titan is an internal analytics platform, and Redmond restricts access via its web interface to Microsoft employees. Faav, with an assist from an AI hackbot he built called Antares, found that he could access Titan’s API through an Azure Cloud Services host because Titan didn’t check the signature on a login token. Microsoft has since locked down the API and paid Faav a $5,000 bug bounty for his research. He says the breakthrough came after 10 days of authentication errors, when he returned to the problem after finishing Friday’s schoolwork and finally managed to execute SQL as a Titan admin after 1 AM Saturday. “It was 2 AM,” Faav said in a blog about his findings. “I wanted to yell, or at least say something out loud, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again.” He also notes that he rewrote his blog post at Microsoft’s request, cut sections and numbers, and reworded the impact prior to publication. “We appreciate the opportunity to investigate the findings reported by Faav,” Microsoft said in a statement provided to Faav for his blog. “Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future.” A boy and his bot The research began on August 25 when Antares found Titan’s public API. For the next 10 days, the human and bot tested the service’s JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs), eventually finding an unsigned token that could reach Titan’s local user lookup - but not a UPN that Titan recognized. Early on September 5, Faav changed the unsigned token’s UPN from an email-formatted identity to admin. Titan recognized it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL. The takeaway, according to Faav: Titan validated the contents of the JWT (tenant, audience, app ID, user) but never verified the signature, the most important part of any authentication check. The authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room. Despite all the access-control logic existing in the app, the one missing piece made it all pointless. If you’re a developer (or coding agent) reading this, the most important takeaway from this post is to make sure you verify signatures above all else when building auth. This gave Faav access to Titan’s platform metadata database, and from there he could query application tables directly. The metadata contained: About 25,000 account and email records. 17,990 employee email records. 15,001 employee organization records. 355 database configurations. 20,979 virtual-dataset SQL definitions. 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions. Titan’s user and usage directory exposed employee job titles, departments, and management hierarchy, which the researcher notes could be useful for social-engineering attacks - “though I never tested or demonstrated that,” he added. He also found a Bing analytics sample and tested two rows that contained search info, identifiers, and high-level location information, such as country- or state-level details. Faav said the location values did not contain precise user locations. 17.3 trillion data rows Then he hit the jackpot, testing 56 routing values from an archived configuration and discovering 30 were still active. “Each routing value pointed to a backend configuration, and each configuration contained one or more databases, so the 30 live values resolved through 24 configurations to 17 connected analytics databases spanning 9,863 unique table names,” the bug hunter wrote. The total comes to about 17.3 trillion rows, which Faav says is a storage estimate derived from metadata and likely includes historical, duplicated, and derived data. “But quite the high number nonetheless.” Between September 6 and September 8, Microsoft asked the teen to stop testing and requested his IP address to confirm no nefarious activity beyond the bug bounty research. A day later, Redmond locked down the endpoint and told Faav the “report prompted immediate investigation and remediation to address the remaining exposure.” Microsoft awarded the bug hunter $5,000 for his work on September 17.®