CVE-2026-87803: High severity Countly Countly Server DBViewer vulnerability

Published Sep 10, 2026
·
Updated

An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWNSTAGEOPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.

Affected Software

1 affected component
Countly Countly Server DBViewer

Event History

Sep 10, 2026
CVE Published
via MITRE·09:54 AM
Data Sourced
via MITRE·09:54 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An authenticated non-admin user who has DBViewer read permission can exploit it. The vulnerable path is the /o/db aggregation endpoint.

2

What access does an attacker need to obtain sensitive data?

The attacker must be able to submit aggregation JSON to DBViewer and use a nested $facet sub-pipeline. By including an unrecognized stage key such as $_internalInhibitOptimization, they can cause sibling forbidden stages, including $lookup, to bypass sanitization and join restricted collections.

3

What is the impact of successful exploitation?

Successful exploitation provides unauthorized read access to restricted collection data. The described exposed data includes password-reset tokens (prid), which can enable account takeover.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203