A security flaw in Titan, Microsoft’s analytics service, could have allowed a 16-year-old security researcher to access over 17 trillion records.
According to Faav, the security researcher who discovered the vulnerability, Titan did not verify login tokens, allowing him to gain administrative rights on 17 connected databases and execute raw SQL queries.
For ten days, the teenage researcher used Antares, an artificial intelligence-powered hacking tool he built to bypass various login errors, before taking the final step himself by following his hunch.
Faav says neither Antares nor he could have accomplished the feat alone, underscoring AI’s growing role in cybersecurity.
“Antares wouldn’t have gotten here alone, and neither would I. Its persistence, plus one human hunch, is what made this find possible,” Faav said.
Security flaw in Microsoft Titan exposes unsecured API endpoint
According to Faav, Titan’s frontend interface was only accessible via Microsoft’s VPN. However, his AI bug-hunting tool searched various Microsoft subdomains and discovered a different endpoint that resolved to a Microsoft Azure Cloud Services and exposed four routes:
/GetConfiguration /GetOnboardedTables /v2/Query /v2/Insert
Of the four routes, three required Azure AD bearer authentication, but /v2/Query did not and also accepted raw SQL.
After trying various requests, the security researcher discovered that the endpoint rejected requests without an authorization header. Nevertheless, his AI-powered bug-hunting tool kept probing, trying hundreds of leads.
Faav tried his Entra test tenant, which he had used numerous times for testing. However, Titan rejected the request and threw a tenant error.
“Changing the tenant to Microsoft’s reached an audience error. Changing the audience hit an application allowlist error. Changing the application ID finally reached a user lookup,” Faav explained.
According to Ensar Seker, CISO at SOCRadar, the exploitation of the security flaw makes an interesting case for combining automation and human security expertise.
“The AI system handled repetitive discovery, enumeration, and authentication testing over several days, while the decisive breakthrough came from the researcher questioning an assumption about how the application interpreted the user identity field,” Seker said. “That is likely a preview of how both offensive security research and defensive testing will evolve: AI can dramatically increase the speed and breadth of investigation, but human intuition and contextual reasoning remain critical.”
Microsoft Titan does not verify login token signatures, exposing 17 trillion records
Interestingly, the teenage security researcher discovered that, while the payload kept changing, the signature remained the same. He compared Titan to a bouncer who checks IDs without verifying if the photo ID matches the bearer’s face.
“That was the first big clue it wasn’t verifying signatures,” the researcher noted.
Having previously exploited an unsigned JWT bypass and noticed the pattern, the cybersecurity researcher replaced the token with a synthetic JWT.
The payload accepted the supplied values, cleared tenant, audience, and application errors, and returned the User Principal Names (upn) field, which was an email-formatted Entra ID.
Changing the algorithm to ‘none’ and leaving the signature empty passed every authentication check and reached ‘user lookup,’ but returned a ‘user not found’ error.
“This is a strong example of how one fundamental authentication mistake can undermine multiple layers of otherwise well-designed access controls,” Seker added. “Titan was validating information inside the JWT, such as the tenant, audience, and application, but according to the researcher, it was not verifying the cryptographic signature. If an attacker can control the claims without proving who issued the token, those downstream checks provide very little protection.”
Faav’s AI bug-hunting tool Antares tried email-style addresses in the token’s upn field. However, changing the upn value to ‘admin’ treated the field as a local username and matched it to user ID 1 with administrative privileges, allowing the researcher to run SQL queries.
Faav identified 25,000 account and email entries, 17,990 employee email records, 15,001 employee organization records, 355 database configurations, 20,979 virtual-dataset SQL definitions, 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions.
The researcher noted that the exposed employee information included job titles, departments, and management hierarchy. That information could enable malicious actors to execute social engineering attacks.
The researcher also accessed the Bing analytics source, which included search, identifier, and location fields. The location field contained country or state-level information derived from reverse IP lookups.
Based on the database metadata, the researcher estimated that the security flaw could have exposed 17.3 trillion records, potentially including duplicates and historical data. However, the security researcher did not access PII or test for social engineering attacks. He also found no evidence that malicious actors had exploited the security flaw.
On September 5, 2026, Faav notified the Microsoft Security Response Center (MSRC) of the security flaw and received a $5,000 bug bounty. Microsoft also edited his post to minimize the impact of the security flaw.

