A 16-year-old researcher named Faav found that Microsoft’s Titan analytics service failed to verify login token signatures, allowing administrator access and SQL queries across 17 connected databases. The issue exposed employee records and Bing search analytics, and Microsoft later locked down the endpoint after coordinated disclosure. #Titan #Microsoft #Faav #MSRC #Antares #Entra #Bing
Keypoints
- Titan accepted unsigned or altered login tokens.
- Faav used his Antares tool to test Titan’s authentication flow.
- Changing the token’s claims eventually granted admin access.
- The flaw exposed employee email and organization records, plus Bing analytics samples.
- Microsoft patched the endpoint and awarded Faav a $5,000 bounty.
Read More: https://www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/