Build2 publishers2 min readPublished
A skipped token-signature check let a teenager run admin queries on Microsoft's Titan
Faav, 16, impersonated an administrator on Microsoft's internal Titan service with an unsigned token, reaching an estimated 17.3 trillion rows. Microsoft disabled the API four days after his report and paid a $5,000 bounty.
The Engineer · Build desk

What happened
- Titan's documentation listed four API routes; three required Azure Active Directory bearer authentication, but the fourth, /v2/Query, accepted raw SQL and specified no such check.
- Faav's AI tool Antares found the API on a publicly reachable Azure host on August 25th, even though Titan's web interface showed a page saying a VPN was required.
- Beyond the analytics rows, the service exposed about 25,000 application account and email records, 17,990 employee email records and 15,001 employee-organization records.
- Faav says the row total is a metadata-based estimate of stored rows, not a count of unique people or of confirmed records he took.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint A JSON Web Token's signature is the part that binds its claims to a trusted issuer; because Titan checked several claims and never the signature, every check it ran was validating values the caller could set.
- exposure Because /v2/Query accepted raw SQL with no authentication requirement, the only barrier left between a caller and the databases was a token check that never verified the token.
- precedent The service was internal to Microsoft and the failure was still a skipped signature check, so the same gap is worth testing anywhere a service trusts token claims without verifying the signature.
Faav found the gap by watching how Titan answered him. He changed claims in a test JSON Web Token and got new responses as the service checked the tenant, then the audience, then the application ID, then the user identity. Through all of it the token's signature stayed the same, and Titan never rejected it. He took that as proof the signature was not being validated, and sent a token with no signature at all [9].
The last step was human. Titan read the token's upn field as a local application username. Email-formatted identities failed, so Faav set the value to admin. Titan mapped that name to local user ID 1, which held the administrator role, and ran his query [10]. Antares, the AI tool he built to automate the repetitive probing, had reached the user lookup but never tried a username that was not an email address [23]. Faav says he saw the possibility himself after coming back to the lead past 1 a.m. on September 5th [11].
Faav wrote that AI and human intuition compounded in this case. In his account, Antares did ten days of work he did not have to do, and its persistence plus one human hunch made the find possible [20].
The row estimate deserves the caution he gave it. He says 30 of the 56 archived routing values were still active, leading through 24 configurations to 17 databases and 9,863 unique table names [12]. He summed row counts from database metadata, checked the total through two paths, and reached 17,333,335,124,315 [13]. To confirm the data was reachable and not only counted, he sampled two rows from a Bing analytics partition and went no further [14]. He says he did not bulk-download customer data or reach personally identifiable customer information [5].
The metadata was the more concrete exposure. Some of the employee records carried job titles, departments and management hierarchy for staff tied to Titan, and Faav says he did not test whether that could be used for social engineering [16].
Faav reported the flaw to the Microsoft Security Response Center [3]. Microsoft said his submission and coordinated disclosure helped it harden its services [18]. He also disclosed that Microsoft had editorial control over his Titan writeup and asked for sections and figures to be cut or reshaped before publication, while the 17.3 trillion figure stays his [19]. This was his second public Microsoft disclosure; in July 2025, at 15, he reported exposure in Microsoft Guest Check-In [17]. He says he has "spent the year hacking Microsoft off and on around school" [21].
What to watch
- Whether Microsoft issues a CVE or post-incident writeup beyond its statement that the disclosure helped it harden services.
- Whether other internal Microsoft services handle unsigned tokens the way /v2/Query did.
- Whether the editorial control Microsoft had over Faav's post changed the scope figures he published.