A 16-year-old researcher who goes by Faav found an authentication flaw in Microsoft’s Titan analytics service that let him act as an administrator and run unapproved SQL queries without valid credentials. With help from an AI agent he built, called Antares, he reached analytics databases holding an estimated 17.3 trillion rows.
Titan is an internal platform, and Microsoft normally limits its web interface to employees. Faav found he could reach Titan’s API through an Azure Cloud Services host because the service validated a login token’s contents but never checked its signature. Changing an unsigned token’s identity to “admin” resolved to local user ID 1, which carried the admin role. He said the flaw was like a hotel where every keycard opened every room.
He could then read metadata covering roughly 25,000 accounts, nearly 18,000 employee emails, and thousands of dashboard and dataset definitions. He also found 30 live routing values that fanned out to 17 connected databases across 9,863 tables. Microsoft asked him to stop testing, locked down the endpoint, and awarded him a $5,000 bounty on September 17. The researcher said he rewrote his write-up at Microsoft’s request before publishing.
