CVE-2026-87803

Source
https://cve.org/CVERecord?id=CVE-2026-87803
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87803.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-87803
Published
2026-09-10T09:54:01Z
Modified
2026-09-12T03:47:21Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWN_STAGE_OPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $_internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.

Database specific
{
    "cna_assigner": "snyk",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87803.json"
}
References

Affected packages

Git / github.com/countly/countly-server

Affected ranges

Type
GIT
Repo
https://github.com/countly/countly-server
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "25.03.53-LTS"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

16.*
16.02.1
16.06
22.*
22.03.6
22.09.10
22.09.11
22.09.12
22.09.13
22.09.14
22.09.15
22.09.16
22.09.17
22.09.18
22.09.19
22.09.8
22.09.9
22.09.test
23.*
23.03
23.03.1
23.03.2
23.03.3
23.03.4
23.03.5
23.03.6
23.03.7
23.03.8
23.03.9
23.06
23.06.1
23.06.10
23.06.11
23.06.12
23.06.13
23.06.14
23.06.15
23.06.16
23.06.2
23.06.3
23.06.4
23.06.5
23.06.6
23.06.7
23.06.8
23.06.9
23.11
23.11.1
23.11.10
23.11.11
23.11.12
23.11.13
23.11.14
23.11.15
23.11.16
23.11.17
23.11.18
23.11.19
23.11.2
23.11.20
23.11.21
23.11.22
23.11.3
23.11.4
23.11.5
23.11.6
23.11.7
23.11.8
23.11.9
23.11.test
23.7.11.hooks-vm
24.*
24.03.4
24.05
24.05.1
24.05.10
24.05.11
24.05.12
24.05.13
24.05.14
24.05.15
24.05.16
24.05.17
24.05.18
24.05.19
24.05.2
24.05.20
24.05.21
24.05.22
24.05.23
24.05.24
24.05.25
24.05.3
24.05.36
24.05.5
24.05.52
24.05.6
24.05.7
24.05.8
24.05.9
24.10.12
25.*
25.03.0
25.03.11
25.03.12
25.03.13
25.03.14
25.03.15
25.03.15.test
25.03.16
25.03.17
25.03.18
25.03.19
25.03.2
25.03.20
25.03.21
25.03.22
25.03.23
25.03.24
25.03.25
25.03.26
25.03.27
25.03.28
25.03.29
25.03.3
25.03.30
25.03.31
25.03.33
25.03.34
25.03.35
25.03.36
25.03.37
25.03.38
25.03.39
25.03.4
25.03.40
25.03.41
25.03.42
25.03.43
25.03.44
25.03.45
25.03.46
25.03.47
25.03.48
25.03.49
25.03.5
25.03.50
25.03.51
25.05.4
Other
SERVER-1658
countly-server-v13.*
countly-server-v13.06
v13.*
v13.10
v14.*
v14.08
v16.*
v16.12
v17.*
v17.05
v17.09
v18.*
v18.01
v18.01.1
v18.04
v18.04.1
v18.08
v19.*
v19.02
v20.*
v20.11
v20.11.1
v20.11.2
v21.*
v21.11
v21.11.1
v21.11.2
v21.11.3
v21.11.4
v22.*
v22.03
v22.03.1
v22.03.10
v22.03.11
v22.03.12
v22.03.2
v22.03.3
v22.03.4
v22.03.5
v22.03.6
v22.03.6.1
v22.03.6.2
v22.03.7
v22.03.8
v22.03.9
v22.06
v22.06.1
v22.06.2
v22.06.3
v22.06.4
v22.06.5
v22.08
v22.08.1
v22.08.2
v22.08.3
v22.08.4
v22.08.5
v22.08.6
v22.09
v22.09.1
v22.09.2
v22.09.3
v22.09.4
v22.09.5
v22.09.6
v22.09.7
v22.09.test
v22.09.test1
v22.09.test2
v22.09.test3
v25.*
v25.03.10
v25.03.32
v25.03.6
v25.03.7
v25.03.8
v25.03.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87803.json"