The bug sat in Titan, a Microsoft internal API that did not verify token signatures. The researcher reported it on September 5; Microsoft locked the endpoint four days later.
A 16-year-old security researcher says a missing token-signature check in a Microsoft internal API called Titan let them reach admin access across a surface the company holds an estimated 17.3 trillion rows of metadata deep.
The researcher, publishing as Faav, disclosed the finding September 25 and says the bypass came from swapping an identity value for a local administrator username on September 5. After that, a bounded SQL query succeeded. The post attributes the flaw to Titan not verifying token signatures, and traces the work to roughly ten days of token-validation probing by an agent called Antares, built on Codex and Claude.
Faav says they ran two one-row Bing samples and never touched the wider dataset. That "no customer data" claim sits beside descriptions of employee records and bounded Bing rows in the same disclosure, a tension the post does not fully resolve.
Microsoft's acknowledgment appears inside the researcher-controlled blog; the company has not, in materials reviewed here, independently validated the row-count estimate. The report reached the Microsoft Security Response Center on September 5 and the endpoint was locked down September 9, per the disclosure.
A CVE-2026-45585 record surfaced in coverage identifies a Windows BitLocker issue, not Titan, so it does not corroborate this finding. The Register also covered the disclosure.