16-year-old found Microsoft bug, got admin access to 17.3T-row databases
Faav, a 16-year-old security researcher, discovered an authentication flaw in Microsoft’s Titan internal analytics service. Titan is restricted through its web interface to Microsoft employees, but the vulnerability let him gain administrator access, submit unauthorized SQL queries without valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows. He found the issue with help from an AI hackbot he built called Antares, and was able to access Titan’s API through an Azure Cloud Services host because Titan did not check the signature on a login token.
Microsoft has since locked down the API and paid Faav a $5,000 bug bounty for his research. According to Faav, the breakthrough came after 10 days of authentication errors; he returned to the problem after finishing Friday’s schoolwork and finally executed SQL as a Titan admin after 1 a.m. Saturday. He described the moment in his blog: “It was 2 AM. I wanted to yell, or at least say something out loud, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again.” He also noted that he rewrote his blog post at Microsoft’s request, cutting sections and numbers and rewording the impact prior to publication.
Microsoft said in a statement provided to Faav for his blog that it appreciated the opportunity to investigate the findings, that his coordinated vulnerability disclosure helped protect customers by hardening its services, and that it values safe security research under the Microsoft Bug Bounty Program and looks forward to continuing to work with him.
The technical timeline began on August 25, when Antares found Titan’s public API. For the next 10 days, the human and bot tested the service’s JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs), eventually finding an unsigned token that could reach Titan’s local user lookup—but not a UPN that Titan recognized. Early on September 5, Faav changed the unsigned token’s UPN from an email-formatted identity to “admin.” Titan recognized it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL.
Faav’s takeaway was that Titan validated the contents of the JWT—tenant, audience, app ID, and user—but never verified the signature, the most important part of any authentication check. He compared the authentication checks to a hotel where every door had a working keycard reader, but any keycard unlocked any room: despite all the access-control logic existing in the app, the one missing piece made it all pointless. His advice to developers (or coding agents) reading the post is to make sure they verify signatures above all else when building auth.