A 16-Year-Old Found a Flaw That Could Have Unlocked 17 Trillion Microsoft Records

I Could've Accessed 17T Microsoft Records

A 16-Year-Old Found a Flaw That Could Have Unlocked 17 Trillion Microsoft Records

Faav, a 16-year-old bug bounty hunter, discovered that Microsoft's internal Titan analytics service never verified JWT signatures. By crafting an unsigned token with the username 'admin', he executed SQL queries as an administrator. The exposed data included 17,990 employee emails, 25,000 account records, and an estimated 17.3 trillion rows across 17 analytics databases. Microsoft fixed the issue and acknowledged his coordinated disclosure.

Titan validated the contents of the JWT (tenant, audience, app ID, user) but never verified the signature, the most important part of any authentication check. The authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room.
  1. john_strinlai

    >Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.

    that is... not great. shame on microsoft.

    its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.

  2. sdfhbdf

    > awarded $5000

    It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

    On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

    What does HN think? Why would it be only $5000?

  3. throwaway2037

    > Hey! I’m Faav. A little over a year ago, when I was 15, I published Break into any Microsoft building: Leaking PII in Microsoft Guest Check-In, my first Microsoft write-up. I’m 16 now, and this one is a little bigger.

    Damn, these guys got schooled by a 15 year old! Say less...

  4. verst

    There is an internal library at Microsoft that reliably avoids all these JWT problems - Microsoft Identity Service Essentials (MISE). Adopting MISE and upgrading to the latest versions of it have been part of the Secure Future Initiative (SFI) that can be read about in the news of previous years. Unfortunately it sounds like the service team intentionally deferred the compliance alerts they will have received.

  5. rdtsc

    > {"alg":"none","typ":"JWT"}

    I don't know how this ever became a thing that was allowed into the spec and then picked from the spec and implemented in various implementations.

  6. er0k

    wow I am so surprised to hear once again how JWTs are terrible

    https://www.howmanydayssinceajwtalgnonevuln.com/

  7. zk

    The kicker... only 5k reward for this is insane. That said probably the attacker didn't need to run as many queries as they did...

    09/17/26 - Awarded $5,000

  8. f311a

    What is Antares? Can't find anything related to it except for the 1B model, which does not seem to be capable of autoresearch.

    UPD: It's his personal bot.

More from this day

2026-09-30