CVE-2026-92565

Summary

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.

Affected Software

VendorProductVersion RangeStatus
lukevellarallly0 < 4.15.0affected
lukevellarallly4.15.0unaffected

Weaknesses

  • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor

References