PatchSiren

lukevella CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM lukevella CVE published 2026-09-16

CVE-2026-92565

CVE-2026-92565 is an information disclosure vulnerability in Rallly before version 4.15.0. The vulnerability exists in the polls.get tRPC procedure, which returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can exploit this by accessing a poll's urlId from public invite links to retrieve sensitive invitee information, regardless of privacy settings.