Vulnerabilities & Exploits · Web App Attack

Microsoft Titan Token Check Opened Admin SQL Access

A 16-year-old researcher known as Faav disclosed that Microsoft’s internal Titan analytics service accepted forged login tokens and let him reach administrator SQL access across about 17.3 trillion rows. The finding came through coordinated disclosure, and the service was internal rather than public-facing.

Titan was checking the claims inside the token but not reliably verifying the signature, so a token with altered fields could still pass as valid. Faav showed that setting the token algorithm to "none" and changing the username field to "admin" was enough to be treated as user ID 1, which had the Admin role.

For Microsoft internal platform owners, the lesson is that the trust boundary sits in token validation, not in network reachability. If a data platform accepts a believable but forged token, it can hand out administrator rights to shared datasets even when the login path itself looks locked down.

1 source · 8h ago

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-28

Every edition of this story: Microsoft Titan Token Check Opened Admin SQL Access

More from today