• Sources: primary, discussion
  • Summary: The service checked tenant, audience, application id and user claims on the bearer token but never checked the signature, so a token with an alg: none header and an empty signature section passed every other control, and setting the upn claim to the literal string admin resolved to local user id 1 holding the Admin role and allowed raw SQL. The writeup counts 30 live routing targets resolving through 24 configurations to 17 connected ClickHouse analytics databases across 9,863 table names, with a metadata row estimate of 17,333,335,124,315 verified through two paths. Microsoft locked the endpoint on 2026-09-09, four days after the 2026-09-05 report, awarded $5,000 on 2026-09-17, supplied a statement, and had editorial control over the post, cutting sections and figures before publication.
  • Why it matters: Validating every claim while skipping the signature leaves each claim attacker-controlled, and the author states his own AI hunting tool spent ten days on enumeration and JWT probing without ever trying admin, because the field name says UPN.
  • Follow-up: Track whether Microsoft publishes its own account of the exposure, and whether the cut sections and figures are released.

send feedback on this story