Microsoft Flaw: An Unsigned Token Logged In as Admin

A 16-year-old researcher who goes by Faav got administrator access to Titan, an internal Microsoft analytics service. He used an unsigned access token and the username "admin". He published the case on September 25, 2026. Microsoft closed the hole on September 9. The lesson applies to any website with a login, a dashboard or an API.

What we know

  • Who and when: Faav published the write-up on his blog on September 25, 2026. The Register covered it on September 30.
  • What Titan is: by his account, an internal Microsoft service for running SQL queries against several analytics databases. The web page asked for a VPN, but the API behind it answered from the public internet and listed its routes openly.
  • The flaw: the API accepted unsigned JWT tokens, with the algorithm set to `none`. It checked several fields in the token but not the signature. Typing `admin` into the username field was enough.
  • How he got there: his own AI tool, which he calls Antares, found the API on August 25 and spent ten days getting past the token checks one by one, without getting in. He made the final step by hand on September 5.
  • Old traces: he pulled 2023 snapshots of Titan pages from the Wayback Machine. They gave him table definitions.
  • What he saw: about 25,000 account and email records from the application, 17,990 employee email records and two sample rows of Bing analytics. He says he did not touch customer data.
  • The big number: 17.3 trillion rows across 17 databases. It is an estimate from metadata. The author himself warns it likely includes historical, duplicated and derived data.
  • Timeline: he reported it to Microsoft on September 5. The API was locked down on September 9. He was awarded $5,000 on September 17.
  • Microsoft: in a statement the author reproduces in his write-up and The Register also carries, the company thanked him and said the report helped it harden its services. The author says Microsoft reviewed the write-up before publication and asked for sections and figures to be cut.

What changes and what doesn't

Nothing changes on your website because of this case. The flaw was in an internal Microsoft service and has been closed since September 9.

The excuse changes. This is not a new mistake: the JWT best-practices guide, RFC 8725, has described the attack of setting the algorithm to "none" since February 2020. The cost of looking changes too: an AI tool found the exposed API on its own. A person supplied the last step.

Read it with care. The whole account comes from the researcher, and Microsoft had a hand in the text. We have not seen a Microsoft report or a CVE identifier. The 17.3 trillion rows are what could have been queried, not what was queried. Neither the author nor The Register says anyone else used the flaw. That does not prove nobody did.

How to tell if it affects you

It affects you if your site has an admin panel, an API or internal tools. Six checks:

  1. The "admin" user. If an account is called admin or administrator, create one with a different name and retire the old one.
  2. What answers from the internet. A page that asks for a VPN or a password does not mean the API behind it does. Test it from outside, logged out.
  3. Tokens. If your site or app uses JWT, ask whoever built it whether an unsigned token is rejected. RFC 8725 says to fix the list of accepted algorithms and reject the whole token if any check fails.
  4. API documentation. An open Swagger or OpenAPI file shows your routes to anyone. If it does not need to be public, close it.
  5. Old copies. Look up your domain in the Wayback Machine. Test pages and login pages from years ago may still be there.
  6. Least privilege. One account should not reach every database. Each tool gets only what it needs.

The author puts it this way in his write-up: "verify signatures above all else."

How we apply it at DomHostSeo

We build sites on Drupal and WordPress, and our maintenance plans cover plugin, theme and core updates, backups and monitoring. This case sits one step earlier, in permissions: who gets in, under which username, and how far they can reach.

We use AI to write and illustrate, within rules and checks we wrote ourselves. Something similar happened here: the tool found the door, and the idea that opened it came from a person.

For this story we opened the researcher's write-up and RFC 8725. We read Microsoft's statement in the author's write-up and in The Register, not on a Microsoft page, so we attribute it. It is the rule we described in Google: Fact-Check AI Content by Hand Before Publishing: the source first, then the story.

Sources

Updates: we will add Microsoft's own report or a CVE identifier here if either is published.