Security1 publisher2 min readPublished
Missing token signature check gave a 16-year-old admin SQL on a Microsoft analytics service
Faav, a 16-year-old researcher, reached admin SQL over 17.3 trillion rows on Microsoft's Titan service because it never checked login-token signatures. Microsoft locked the endpoint four days after his report and paid a $5,000 bounty.
The Watch · Security desk

What happened
- Titan's web console sat behind a Microsoft VPN, but its API endpoint was publicly documented and one route, /v2/Query, accepted raw SQL.
- The platform metadata he could read held about 25,000 account and email entries, 17,990 employee email records and 15,001 organization records with job titles and management hierarchy.
- He also reached a Bing analytics source and pulled two one-row samples carrying search, identifier and location fields down to country or state level.
- Antares, the automated bug-hunting tool he built himself, flagged Titan and spent ten days working through its login checks before he finished by hand.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability The whole authentication rested on one check. Anyone who found the documented API and forged a token with no valid signature could have run admin SQL against the connected databases.
- exposure An attacker with the same access would have had job titles, departments and reporting lines for part of Microsoft's workforce to build targeted phishing, a use Faav flagged but did not try.
- contradiction The reporting counts access to 17 trillion rows, but Faav calls 17.3 trillion a storage estimate from metadata that likely includes historical, duplicated and derived data, so it is not a count of unique records.
Titan refused any request that arrived without an authorization header, so a valid-looking token was the only lock on the door [6]. It never checked whether that token was genuine [3]. Faav started with a JWT from an external Entra test tenant he had built months earlier. Titan answered with a tenant error, then an audience error, then an application allowlist error, then a user lookup, as he edited one claim at a time and left the signature untouched [10].
"The payload kept changing while the signature stayed exactly the same, and Titan kept accepting the new claims, like a bouncer checking the name on every ID but never looking at the photo. That was the first big clue it wasn't verifying signatures," Faav wrote [9].
He then sent a token with its algorithm set to none and an empty signature. It passed every check and reached the user lookup, which returned "user not found" [7]. For days the tool cycled through email-style addresses in the token's upn field. On September 5 he set the field to admin. Titan read it as a local username, matched user ID 1, and handed back the Admin role [8].
The same MUID browser identifiers turned up in more than one of the datasets he could reach, which Faav said made it plausible to correlate a user's activity across services [14]. He said he never touched customer data or personal information [20].
He reported the flaw to the Microsoft Security Response Center on September 5, and MSRC asked him to stop testing and hand over his IP address to confirm there had been no activity beyond his research [18]. The endpoint was locked down on September 9, and the bounty followed on September 17 [19].
Faav gave the credit to the tool and one guess. "Antares wouldn't have gotten here alone, and neither would I. Its persistence, plus one human hunch, is what made this find possible," he wrote [17]. Microsoft, in a statement in his write-up, said the report "helped us to better protect our customers by hardening our services" [21].
What to watch
- Whether MSRC audits other Titan-connected databases and internal APIs for the same missing signature check.
- Whether Faav releases Antares or publishes more of what the tool surfaced.
- Whether any of the reachable employee records or Bing samples turn up later in phishing.