MEDIUM
lukevella
CVE published 2026-09-16
CVE-2026-92565
CVE-2026-92565 is an information disclosure vulnerability in Rallly before version 4.15.0. The vulnerability exists in the polls.get tRPC procedure, which returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can exploit this by accessing a poll's urlId from public invite links to retrieve sensitive invitee information, regardless of privacy settings.