16-year-old found auth bypass in Microsoft Titan analytics service
A teenage researcher known as Faav found that Microsoft's Titan analytics service accepted forged JWTs with the algorithm set to "none", gaining admin access to 17 databases holding an estimated 17.3 trillion rows. Microsoft locked down the API on September 9, 2026, and paid a $5,000 bounty.
- A token with algorithm "none" and username admin granted full admin rights
- 17 ClickHouse databases and about 25,000 accounts were reachable
- The flaw was flagged by his AI tool Antares on August 25
- Microsoft locked the API on September 9 and paid $5,000 on September 17
Read next
Security