Information Disclosure Vulnerability in Rallly by Lukevella
CVE-2026-92565

6.9MEDIUM

Key Information:

Vendor

Lukevella

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92565?

Rallly prior to version 4.15.0 is vulnerable to an information disclosure issue in its polls.get tRPC procedure. This vulnerability allows unauthorized access to sensitive information, specifically the names and email addresses of scheduled-event invitees. Attackers can exploit this flaw by leveraging publicly available poll invite links to retrieve confidential information without authentication. This poses significant risks to user privacy, as it circumvents intended privacy settings and exposes critical data to potential misuse.

Affected Version(s)

rallly 0 < 4.15.0

rallly 4.15.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.