Authorization Bypass in Countly Server's DBViewer
CVE-2026-87803
7.1HIGH
What is CVE-2026-87803?
An authorization bypass vulnerability in Countly Server's DBViewer allows non-admin users to inject unauthorized operators into aggregation queries. This occurs due to inadequate checks in the aggregation stage sanitizer, permitting users with read permissions to perform cross-collection joins. Consequently, sensitive information, including password-reset tokens, can be exposed, leading to potential account takeovers.
Affected Version(s)
countly-server 0
