A 16-year-old security researcher, Faav, discovered a flaw in Microsoft’s Titan analytics service, potentially exposing 17.3 trillion database rows. The investigation, which began on August 25, 2026, relied on metadata, table descriptions, and limited samples, and Faav found no evidence of customer personally identifiable information (PII) being accessed. The researcher found archived Titan pages containing 56 table definitions and a routing value named TestData, providing sufficient information to commence controlled testing.

Microsoft’s Titan Analytics Vulnerability The service validated the tenant ID, audience, application ID, and user identity but continued processing altered claims while the original signature remained unchanged.

The breakthrough occurred when Faav reconsidered how the backend interpreted the upn field and replaced it with "admin." Titan mapped the value to local user ID 1, assigned the Admin role, and successfully executed a SELECT 1 query. Accessible metadata reportedly included approximately 25,000 account and email records, 17,990 employee email entries, 15,001 employee organization records, 355 database configurations, 20,979 virtual-dataset SQL definitions, 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions.

Applications must cryptographically verify token signatures, reject unsigned tokens, restrict approved algorithms, validate issuer and audience values, and avoid mapping attacker-controlled claims to privileged local accounts. In Titan’s case, a missing signature check compromised several access-control layers, turning a public analytics endpoint into a potential gateway to Microsoft’s extensive data environment.