Tech News
← Home  ·  All topics

Jwt Vulnerability

1 GoKawiil brief on this topic

Researcher finds Microsoft internal API flaw exposing 17T database rows

Security researcher Faav discovered that an internal Microsoft analytics service failed to verify the signature on login tokens, allowing anyone to impersonate an administrator and run unauthorized SQL queries. Faav says the flaw could have exposed roughly 17.3 trillion rows across multiple Microsoft datasets, but reported it through Microsoft's Bug Bounty Program without accessing customer data or PII. Microsoft confirmed it investigated and hardened the affected service in response.