{"id":"CVE-2026-87803","details":"An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWN_STAGE_OPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $_internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.","modified":"2026-09-12T03:47:21.842247760Z","published":"2026-09-10T09:54:01.912Z","database_specific":{"cna_assigner":"snyk","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87803.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87803.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87803"},{"type":"FIX","url":"https://github.com/Countly/countly-server/pull/7868"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/countly/countly-server","events":[{"introduced":"0"},{"fixed":"97f707c495de04766f50875cee08429648149d91"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"25.03.53-LTS"}],"source":"AFFECTED_FIELD"}}],"versions":["25.03.51","24.05.52","25.03.50","25.03.49","25.03.48","25.03.47","25.03.46","25.03.45","25.03.44","25.03.43","25.03.42","25.03.41","25.03.40","25.03.39","25.03.38","25.03.37","25.03.36","25.03.35","25.03.34","25.03.29","25.03.33","v25.03.32","25.03.31","25.03.30","25.03.28","25.03.27","25.03.26","25.03.25","25.03.24","25.03.23","25.03.22","25.03.21","25.03.20","25.03.19","25.03.18","25.03.17","25.03.16","25.03.15.test","25.03.15","25.03.14","25.03.13","25.03.12","24.10.12","24.05.36","25.03.11","v25.03.10","v25.03.9","v25.03.8","v25.03.7","v25.03.6","25.03.5","25.03.4","24.03.4","25.03.3","25.03.2","25.03.0","24.05.25","24.05.24","24.05.23","24.05.22","24.05.21","24.05.20","24.05.19","24.05.18","24.05.17","24.05.16","24.05.14","24.05.15","24.05.13","24.05.12","24.05.11","24.05.10","24.05.9","24.05.8","24.05.7","24.05.3","24.05.6","24.05.5","25.05.4","24.05.2","24.05.1","24.05","23.03","23.11.22","23.11.21","23.11.20","23.11.19","23.11.18","23.11.17","23.11.16","23.11.15","23.11.14","23.11.13","23.11.12","23.11.10","23.11.11","23.11.9","23.11.8","23.7.11.hooks-vm","23.11.7","23.11.test","23.11.6","23.11.5","23.11.4","23.11.3","23.11.2","23.11.1","23.11","23.06.16","23.06.15","23.06.14","23.06.13","23.06.12","23.06.11","23.06.10","23.06.9","23.06.8","23.06.7","23.06.6","23.06.5","23.06.4","23.06.3","23.06.2","23.06.1","22.09.19","23.06","23.03.9","23.03.8","23.03.7","23.03.6","23.03.5","23.03.4","23.03.3","23.03.2","23.03.1","22.09.18","22.09.17","22.09.16","22.09.15","22.09.13","22.09.14","22.09.12","22.09.11","v22.09.test3","v22.09.test2","v22.09.test1","v22.09.test","22.09.10","22.09.9","22.09.8","22.09.test","v22.09.7","v22.09.5","v22.09.6","v22.09.4","v22.09.3","v22.09.2","v22.09.1","v22.09","v22.08.6","v22.08.5","v22.08.4","v22.08.3","v22.08.2","v22.08.1","v22.08","v22.06.5","v22.06.4","v22.06.3","v22.06.2","v22.06.1","v22.06","v22.03.12","v22.03.11","v22.03.10","v22.03.9","v22.03.8","v22.03.7","v21.11.4","v22.03.6.2","v22.03.6.1","v22.03.6","22.03.6","v22.03.5","v22.03.4","v22.03.3","v22.03.2","v22.03.1","v22.03","v21.11.3","v21.11.2","v21.11.1","v21.11","v20.11.2","v20.11.1","v20.11","SERVER-1658","v19.02","v18.08","v18.04.1","v18.04","v18.01.1","v18.01","v17.09","v17.05","v16.12","16.06","16.02.1","v14.08","v13.10","countly-server-v13.06"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87803.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}