Veille techno
Connexion
Sécurité
6 Sécurité IT-CONNECT · 28/09/2026

Faille JWT non signé donne accès admin à Microsoft

Une faille dans un jeton JWT permet d'obtenir un accès administrateur sur un service interne de Microsoft.

Un chercheur de 16 ans a obtenu un accès admin à Titan, un service d'analyse interne de Microsoft, grâce à une faille liée à un jeton JWT non signé. Le post Faille Microsoft : un jeton JWT non signé donnait un accès admin à 17 300 milliards de lignes a été publié sur IT-Connect .