TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A researcher writing as Faav says Microsoft’s internal Titan analytics API accepted login tokens without verifying their signatures, allowing unauthorized SQL queries under an administrator identity. The researcher estimates 17.3 trillion stored rows were potentially reachable, but says they accessed only metadata and bounded samples, not customer data or personal information. Microsoft says it investigated the report and hardened services; the scale and technical impact were not independently verified in the supplied material.
A security researcher known as Faav says a flaw in Microsoft’s internal Titan analytics API allowed an unsigned login token to be treated as an administrator identity, potentially enabling unauthorized SQL queries against datasets containing an estimated 17.3 trillion stored rows. Faav says the access was used only to inspect metadata and limited sample rows, not customer data or personal information, and Microsoft said it investigated the finding and hardened its services.
In a report published Sept. 25, Faav said an AI-assisted search tool first identified Titan on Aug. 25, 2026. Although the service’s web interface displayed a VPN restriction, the researcher found a separate API endpoint and a public Swagger description listing four routes. One route, /v2/Query, accepted SQL and was not described as requiring Azure Active Directory bearer authentication in the API documentation, Faav wrote. An unauthenticated request initially returned an error.
Faav says further testing showed that Titan checked token claims such as the tenant, audience and application ID but did not validate the token’s cryptographic signature. The researcher reports that changing the token’s user principal name to “admin” led to a successful response and enabled queries. The report says the 17.3 trillion figure describes the estimated rows held across datasets that could be reached, not records the researcher downloaded or inspected in full.
Faav says the investigation involved reviewing table descriptions, metadata and bounded sample rows to establish possible scope. The researcher also disclosed that Microsoft had editorial control over the published account, cutting material and figures and changing how impact was described. The supplied report does not provide a technical advisory, affected service inventory or independent validation of the row estimate.
Potential Reach Across Microsoft Data
The report describes an authentication failure in an internal analytics service rather than a confirmed theft of customer records. If the researcher’s account is accurate, accepting unsigned tokens could let an outsider impersonate a privileged application user and send queries that the service otherwise reserved for authorized users. That creates a risk of data exposure or manipulation, depending on the permissions of the service and the tables available to it.
The scale cited — 17.3 trillion stored rows — signals the reported breadth of the datasets, but it should not be read as a count of records accessed, people affected or data extracted. Faav says no customer data or personally identifiable information was touched. Microsoft’s statement says the disclosure helped it harden services, but the company did not provide details in the quoted response about the scope of the fix or whether any other systems were affected.
The case also illustrates why token validation must include cryptographic verification, not only checks of identity fields inside a token. Those fields can be altered unless the service verifies that the token was issued and signed by a trusted authority. The report’s claims about the specific implementation have not been independently confirmed in the supplied material.
As an affiliate, we earn on qualifying purchases.
How the Titan Investigation Developed
Faav’s account says an automated lead-finding tool called Antares identified Titan’s API in late August. The researcher then used archived 2023 pages and configuration information to recover table definitions and a possible table name. A test query without authorization was rejected, prompting a series of experiments with token claims over the following days.
According to the report, errors changed as the token’s tenant, audience and application identifiers were adjusted, while its signature remained unchanged. Faav interpreted that pattern as evidence that Titan checked the claims but not the signature. After unsuccessful attempts with email-formatted user names, the researcher says changing the token’s user principal name to “admin” produced a successful response. The report is dated Sept. 25 and says the issue was reported to Microsoft before publication, but it does not give the disclosure date or a fix date.
Faav also says they had previously published a Microsoft security report and were 16 at the time of this investigation. That personal history is not evidence of the vulnerability’s severity; the central technical and impact claims remain those in the researcher’s account and Microsoft’s brief response.
““We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services.””
— Microsoft, in a statement quoted in Faav’s report
As an affiliate, we earn on qualifying purchases.
Scope and Remediation Details Remain Limited
The supplied report does not identify the datasets behind the 17.3 trillion-row estimate, explain how the estimate was calculated, or provide an independent audit of the access. It also does not establish that all rows were queryable in practice, that the researcher retrieved sensitive information, or that any data was exposed to another party. Faav explicitly characterizes the broader impact as hypothetical.
Microsoft’s quoted response does not name the vulnerable service, describe the corrective changes, state when they were completed or say whether it reviewed logs for possible misuse. The report says Microsoft altered the article before publication, but does not detail those edits. It is also unclear whether the issue was limited to Titan’s query route or whether related services shared the same token-validation weakness.
cybersecurity vulnerability scanner
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Microsoft’s Fix and Review
Microsoft says it investigated the disclosure and hardened services, but has not supplied further remediation or incident-review details in the statement included with the report. The next useful information would be a technical account of which systems were changed, when the fix took effect and whether access logs showed unauthorized queries.
Faav’s published report provides the researcher’s account of discovery and testing, but no additional public milestone or company advisory is identified in the supplied material. Until more detail is released, the reported row count should be treated as a potential scope estimate, not evidence that 17.3 trillion records were accessed or that customer data was compromised.
As an affiliate, we earn on qualifying purchases.
Key Questions
Were 17.3 trillion Microsoft records accessed?
No. Faav describes 17.3 trillion stored rows as an estimate of the potential reach of the service. The researcher says testing was limited to metadata and bounded sample rows and that no customer data or personal information was accessed.
What flaw did the researcher report?
Faav says Titan’s query API accepted a token without checking its cryptographic signature, while still examining claims such as tenant, audience and application ID. The researcher says this allowed a token with an administrator-style user name to reach the query service.
Did Microsoft confirm the vulnerability was fixed?
Microsoft’s quoted statement says it investigated the submission and hardened its services. It does not specify the exact fix, the affected systems or when remediation was completed.
Was customer information exposed?
Faav says no customer data or personally identifiable information was touched. The supplied material contains no independent audit or Microsoft statement about log reviews, so the full extent of any exposure has not been publicly detailed.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
