CVE-2026-87803
Deferred Deferred - Pending Action

Authorization Bypass in Countly Server DBViewer via Aggregation Sanitizer Flaw

Vulnerability report for CVE-2026-87803, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Snyk

Description

An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWN_STAGE_OPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $_internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
countly countly_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Countly Server's DBViewer component. It occurs due to flawed detection of sub-pipelines in the aggregation stage sanitizer. When user-controlled JSON is parsed, the system checks if elements contain keys from a hardcoded set. If an unrecognized key like $_internalInhibitOptimization is present, the sanitizer misclassifies the entire branch as a generic array and skips security checks. This allows non-admin users with DBViewer read permission to inject forbidden operators like $lookup into $facet sub-pipelines, enabling unauthorized cross-collection joins and read access to sensitive data such as password-reset tokens.

Detection Guidance

The vulnerability involves unauthorized access via MongoDB aggregation pipeline manipulation. To detect it, inspect network traffic for requests to the /o/db aggregation endpoint with suspicious $lookup or $_internalInhibitOptimization operators in user-controlled JSON. Check Countly server logs for DBViewer access attempts with complex aggregation pipelines containing undocumented operators.

Impact Analysis

This vulnerability allows a non-admin user with DBViewer read permission to bypass authorization and access sensitive data, including password-reset tokens. Attackers could use this to perform account takeover by resetting passwords for other users. The impact includes unauthorized data exposure and potential compromise of user accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive personal data, violating GDPR's data protection principles and HIPAA's requirements for safeguarding protected health information. Organizations using Countly Server may face compliance violations, regulatory penalties, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Apply the patch from the Countly Server pull request #7868 which refactors the DB Viewer component to validate aggregation operators against an allow-list instead of relying on undocumented internal names. This prevents misclassification of pipelines and blocks unauthorized operators like $lookup.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87803. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart