A security researcher known as Faav discovered a critical authentication flaw in Microsoft’s internal Titan analytics service that allowed unauthenticated attackers to forge administrator JWTs and execute arbitrary SQL queries. Titan reportedly accepted unsigned tokens using the none algorithm and mapped an attacker-controlled upn claim of admin to local user ID 1, granting the Admin role without Microsoft credentials.
Faav limited validation to metadata and one-row queries, reporting no access to customer PII and no evidence that the issue was exploited maliciously. The reachable environment was estimated to contain roughly 17.3 trillion stored rows—an estimate that includes historical, duplicated, and derived data rather than unique customer records or individuals. Microsoft received the disclosure on September 5, restricted the exposed API on September 9, and awarded the researcher a $5,000 bug bounty on September 17.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft awarded Faav a $5,000 bug bounty for the Titan vulnerability report and coordinated publication of the finding.
Microsoft restricted the exposed Titan API endpoint after receiving Faav's report. Faav reported no evidence of malicious exploitation and stated that the controlled validation did not access customer PII.
Faav reported the Titan authentication vulnerability to the Microsoft Security Response Center under case 144051. The flaw allowed a forged unsigned JWT with an attacker-controlled "admin" UPN claim to be accepted as a privileged local account.
Faav's AI-assisted tool, Antares, discovered Microsoft's Titan analytics service and identified a publicly accessible Azure-hosted API despite Titan's web interface displaying a VPN-required page. Faav subsequently found that unsigned JWTs could be used to obtain administrator access and execute raw SQL queries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.