Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-92565

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Sep 16, 2026
Vendor unknown

Description

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.

References