16-year-old researcher found Microsoft Titan auth flaw, got admin access to 17.3 trillion rows
A 16-year-old researcher known as Faav found that Microsoft's Titan analytics service never verified JWT signatures, letting him forge an admin token and reach analytics databases with an estimated 17.3 trillion rows. Microsoft locked down the API and paid him a $5,000 bug bounty.
- Titan failed to verify JWT signatures, allowing a forged token with the username admin
- Access exposed 24,569 dashboards, 425,891 charts and 27,347 dataset definitions
- 24 live configs resolved to 17 connected databases and 9,863 unique table names
- Microsoft fixed the endpoint and paid $5,000 on September 17
Read next
Security