{"id":61443,"date":"2026-09-30T18:29:41","date_gmt":"2026-09-30T18:29:41","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5300240"},"modified":"2026-09-30T18:29:41","modified_gmt":"2026-09-30T18:29:41","slug":"16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/","title":{"rendered":"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"30.159836065574\"> <a data-tag=\"security\" href=\"https:\/\/www.theregister.com\/tag\/security\" class=\"lab-article-section-link\"> <\/p>\n<p class=\" lab-article-section lab-article-section-top \"> security <\/p>\n<p> <\/a> <\/p>\n<p class=\"subtitle below\"> It&#8217;s 2 am. Do you know what your teen is doing? <\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"136.58727445394\"> <!-- placeholder(#1) --> <\/p>\n<p>A 16-year-old security researcher named Faav found an authentication flaw in Microsoft\u2019s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows.<\/p>\n<p>Titan is an internal analytics platform, and Redmond restricts access via its web interface to Microsoft employees. Faav, with an assist from an AI hackbot he built called Antares, found that he could access Titan\u2019s API through an Azure Cloud Services host because Titan didn\u2019t check the signature on a login token.<\/p>\n<p>Microsoft has since locked down the API and paid Faav a $5,000 bug bounty for his research. He says the breakthrough came after 10 days of authentication errors, when he returned to the problem after finishing Friday\u2019s schoolwork and finally managed to execute SQL as a Titan admin after 1 AM Saturday.<\/p>\n<p>\u201cIt was 2 AM,\u201d Faav <a href=\"https:\/\/blog.faav.net\/how-i-couldve-accessed-17-trillion-microsoft-records\" rel=\"nofollow\">said<\/a>&nbsp;in a blog about his findings. \u201cI wanted to yell, or at least say something out loud, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again.\u201d<\/p>\n<p>He also notes that he rewrote his blog post at Microsoft\u2019s request, cut sections and numbers, and reworded the impact prior to publication.<\/p>\n<p>\u201cWe appreciate the opportunity to investigate the findings reported by Faav,\u201d Microsoft said in a statement provided to Faav for his blog. \u201cTheir submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future.\u201d<\/p>\n<h3>A boy and his bot<\/h3>\n<p>The research began on August 25 when Antares found Titan\u2019s public API. For the next 10 days, the human and bot tested the service\u2019s JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs), eventually finding an unsigned token that could reach Titan\u2019s local user lookup &#8211; but not a UPN that Titan recognized.&nbsp;<\/p>\n<p>Early on September 5, Faav changed the unsigned token\u2019s UPN from an email-formatted identity to admin. Titan recognized it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL. The takeaway, according to Faav:<\/p>\n<p><span class=\"font-RobotoMono \" data-lab-fontface=\"RobotoMono\">Titan validated the contents of the JWT (tenant, audience, app ID, user) but never verified the signature, the most important part of any authentication check. The authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room. Despite all the access-control logic existing in the app, the one missing piece made it all pointless. If you\u2019re a developer (or coding agent) reading this, the most important takeaway from this post is to make sure you verify signatures above all else when building auth.&nbsp;<\/span><\/p>\n<p>This gave Faav access to Titan\u2019s platform metadata database, and from there he could query application tables directly. The metadata contained:<\/p>\n<ul readability=\"7.5\">\n<li readability=\"0\">\n<p>About 25,000 account and email records.<\/p>\n<\/li>\n<li readability=\"0\">\n<p>17,990 employee email records.<\/p>\n<\/li>\n<li readability=\"0\">\n<p>15,001 employee organization records.<\/p>\n<\/li>\n<li readability=\"-1\">\n<p>355 database configurations.<\/p>\n<\/li>\n<li readability=\"0\">\n<p>20,979 virtual-dataset SQL definitions.<\/p>\n<\/li>\n<li readability=\"4\">\n<p>24,569 dashboards, 425,891 charts, and 27,347 dataset definitions.<\/p>\n<\/li>\n<\/ul>\n<p>Titan\u2019s user and usage directory exposed employee job titles, departments, and management hierarchy, which the researcher notes could be useful for social-engineering attacks &#8211; \u201cthough I never tested or demonstrated that,\u201d he added.<\/p>\n<p>He also found a Bing analytics sample and tested two rows that contained search info, identifiers, and high-level location information, such as country- or state-level details. Faav said the location values did not contain precise user locations.<\/p>\n<h3>17.3 trillion data rows<\/h3>\n<p>Then he hit the jackpot, testing 56 routing values from an archived configuration and discovering 30 were still active. \u201cEach routing value pointed to a backend configuration, and each configuration contained one or more databases, so the 30 live values resolved through 24 configurations to 17 connected analytics databases spanning 9,863 unique table names,\u201d the bug hunter wrote.<\/p>\n<p>The total comes to about 17.3 trillion rows, which Faav says is a storage estimate derived from metadata and likely includes historical, duplicated, and derived data. \u201cBut quite the high number nonetheless.\u201d<\/p>\n<p>Between September 6 and September 8, Microsoft asked the teen to stop testing and requested his IP address to confirm no nefarious activity beyond the bug bounty research.<\/p>\n<p>A day later, Redmond locked down the endpoint and told Faav the \u201creport prompted immediate investigation and remediation to address the remaining exposure.\u201d Microsoft awarded the bug hunter $5,000 for his work on September 17.\u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5300248&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/30\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-173-trillion-rows\/5300240\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> It&#8217;s 2 am. Do you know what your teen is doing? READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61443","post","type-post","status-publish","format-standard","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-30T18:29:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows\",\"datePublished\":\"2026-09-30T18:29:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/\"},\"wordCount\":767,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/\",\"name\":\"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"datePublished\":\"2026-09-30T18:29:41+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/#primaryimage\",\"url\":\"https:\\\/\\\/image.theregister.com\\\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"contentUrl\":\"https:\\\/\\\/image.theregister.com\\\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/","og_locale":"en_US","og_type":"article","og_title":"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-09-30T18:29:41+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows","datePublished":"2026-09-30T18:29:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/"},"wordCount":767,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/","url":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/","name":"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","datePublished":"2026-09-30T18:29:41+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/#primaryimage","url":"https:\/\/image.theregister.com\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","contentUrl":"https:\/\/image.theregister.com\/5300248.jpg?imageId=5300248&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-17-3-trillion-rows\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61443"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61443\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}