chiprook
← Security
SecurityOctober 5, 2026, 01:23

16-year-old found auth bypass in Microsoft Titan analytics service

A teenage researcher known as Faav found that Microsoft's Titan analytics service accepted forged JWTs with the algorithm set to "none", gaining admin access to 17 databases holding an estimated 17.3 trillion rows. Microsoft locked down the API on September 9, 2026, and paid a $5,000 bounty.

16-year-old found auth bypass in Microsoft Titan analytics service
#Microsoft#Titan#ClickHouse
Read next
Security

Cisco ISE CVE-2026-76460: CVSS 10.0 auth bypass exploited in the wild

Security

Unbound DNSSEC heap overflow and CoreDNS auth bypass disclosed

Security

Kestra CVE-2026-49869: auth bypass via /configs suffix

Security

Four WordPress plugins hit by CVSS 9.8 auth bypass flaws