CVE-2026-92565 MEDIUM

CVE-2026-92565: Rallly before 4.15.0 Information Disclosure via polls.get

Vendor Lukevella
Product rallly
Weakness CWE-359
Published September 16, 2026
Last update September 18, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.

Key dates

02Disclosure timeline

September 16, 2026 CVE published
September 18, 2026 Record updated

Related vulnerabilities

04Related CVE