Home » News » Microsoft Analytics Service Could Be Accessed With...

Microsoft Analytics Service Could Be Accessed With a Forged Admin Token, Researcher Finds

Microsoft Analytics Service Could Be Accessed With a Forged Admin Token, Researcher Finds
Photo: Matthew Manuel / Unsplash.com
Deepanker Verma September 26, 2026 Uncategorized

Add Techlomedia as a preferred source on Google. Preferred Source

A 16-year-old security researcher has discovered an authentication flaw in Microsoft’s internal Titan analytics service that could have allowed administrator access without valid Microsoft credentials. The flaw potentially exposed an analytics environment containing an estimated 17.3 trillion database rows, although the researcher did not access customer data and says the potential impact was hypothetical.

Known online as Faav, the researcher discovered Titan on August 25 while using an AI-powered security research tool called Antares. Although the service displayed a “VPN REQUIRED” page, its API was still publicly reachable through an Azure endpoint. An exposed Swagger document also revealed an endpoint called /v2/Query that accepted SQL queries.

Archived Titan pages provided further information about the service, including 56 table definitions and routing details. Initial requests without authentication were correctly rejected, but further testing revealed that Titan was not properly verifying the signatures of JSON Web Tokens.

That allowed Faav to create an unsigned JWT using the none algorithm. After figuring out how Titan interpreted the user identity in the token, the researcher changed the upn value to admin. Titan mapped it to local user ID 1, which had administrator privileges, and accepted a test SELECT 1 query.

The problem was not that Titan lacked authentication checks. It checked values such as the tenant ID, audience, application ID and user identity. The issue was that those checks relied on claims that could be modified because the token’s signature was never properly verified. In simple terms, the service was checking what the token said without first confirming who had actually issued it.

With administrator access, Faav could reach metadata from Titan’s connected analytics environment. The researcher found information covering thousands of databases, tables, dashboards, charts and datasets. Limited testing also confirmed access to Bing search analytics, but Faav said no individuals were identified, no records were linked across datasets and no customer personally identifiable information was accessed.

Faav then tested the 56 archived routing values and found 30 that were still active. They mapped through 24 configurations to 17 ClickHouse analytics databases containing 9,863 unique table names. Database metadata was used to calculate a combined total of 17,333,335,124,315 rows.

The 17.3 trillion figure needs an important qualification. It does not mean Microsoft had 17.3 trillion customer records exposed, nor does it represent 17.3 trillion unique people. The estimate includes historical, duplicated and derived data and describes the potential database scope reachable through the flaw.

Faav reported the vulnerability to Microsoft’s Security Response Center on September 5. Microsoft locked down the affected API endpoint on September 9 and awarded the researcher a $5,000 bounty on September 17. Faav has published the full technical details of the discovery.

The finding shows a basic but important problem with JWT-based authentication. Validating claims such as a user’s identity or role is not enough. The application must first verify the token’s cryptographic signature, restrict accepted signing algorithms and properly validate the issuer and audience.

In this case, the missing signature check effectively undermined the other authentication controls. A publicly reachable API combined with a forged administrator token could have provided a path into a much larger analytics environment.

There is no evidence that malicious attackers exploited the flaw. Microsoft was notified through responsible disclosure and closed the affected endpoint before the potential access described by the researcher became a confirmed data breach.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.