Microsoft Titan Accepted Unsigned Tokens, and a 16-Year-Old Got Admin
Security / news
Microsoft Titan Accepted Unsigned Tokens, and a 16-Year-Old Got Admin
The 17.3 trillion row figure is a metadata estimate; the records Faav says he confirmed reading number in the tens of thousands.

An unauthenticated attacker who could reach Titan, an internal Microsoft analytics service, could become its administrator by editing one field in a login token, because the service never checked the token's signature. A 16-year-old researcher who goes by Faav did exactly that on September 5, then ran SQL against 17 connected ClickHouse databases. Microsoft locked the endpoint four days later.
The researcher's own writeup and Help Net Security's summary agree on the mechanics. No CVE or severity score has been published for the flaw, so the usual shorthand for ranking it is missing.

What the flaw was, and what it required
Titan accepted JSON Web Tokens without verifying them. Faav crafted a token whose algorithm was set to none and whose signature section was a bare period. He then changed the upn claim, which normally holds an email-formatted identity, to admin. The service granted local administrator access.
The precondition was reaching the service, not holding credentials. No account, password or second factor appears anywhere in the sequence: the only input was a token the attacker wrote themselves.
Faav says his own automated tool, Antares, found the service on August 25 and recovered an archived Superset configuration that exposed 56 table definitions. The tool then spent ten days testing token validation before the admin change worked.
Timeline
| Date (2026) | Event |
|---|---|
| August 25 | Antares identifies Titan |
| September 5 | upn changed to admin; report opened as MSRC case 144051 |
| September 9 | Microsoft locks down the API endpoint |
| September 17 | $5,000 bounty awarded |
| September 22 to 24 | Microsoft reviews the draft disclosure and asks for changes |
| September 28 | Disclosure published |
The 17.3 trillion figure is an estimate
The headline number is 17,333,335,124,315 rows across 17 databases and 9,863 table names. Faav says it is derived from metadata and "likely includes historical, duplicated, and derived data". It is a storage estimate, not a count of people.
What he confirmed he could read is far smaller, and the chart below shows it. He says he never touched customer data or personal information, and that his two Bing queries returned one row each.
- Application user accounts (approx.)25K records
- Employee email records18K records
- Employee organization records15K records
- Database configurations355 records
Source: Faav, blog.faav.net, accessed 2026-09-30
The employee organization records include job titles, departments and management hierarchy, according to Help Net Security. That is the class of data that feeds targeted phishing, which is a different risk from the one the trillion-row figure suggests.
What Microsoft said, and what it changed
Microsoft's statement, quoted in both sources, reads: "We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services."
Faav writes that Microsoft reworded the impact description and removed some sections and figures between September 22 and 24. The published version is therefore the edited one, and the writeup does not say which figures were cut. Microsoft has not published its own account of Titan.
The payout is worth noting beside the scale. A bounty of $5,000 was awarded 12 days after the report, for an administrator-level bypass on a service holding employee directory data.
What operators should take from it
Signature checking is the whole point of a JWT. A library call that decodes a token without verifying it, or that honours the none algorithm, turns identity into a string the client chooses. Pin the accepted algorithms server-side and reject unsigned tokens.
Titan has no CVE, so it will not appear in the catalogues we track, such as the CISA exploited-flaw entries we covered for Linux or Apple's CoreGraphics zero-day. Neither source reports exploitation by anyone else. Microsoft has not said whether it searched its logs for earlier use, and until it does that question stays open.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.