Description
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Rallly before version 4.15.0 exposes the names and email addresses of poll invitees through the polls.get tRPC procedure to anyone who can call it. The vulnerability allows an unauthenticated attendee to enumerate sensitive personal data regardless of the poll’s privacy settings, effectively leaking personally identifying information to external observers.

Affected Systems

All installations of Rallly produced by lukevella before release 4.15.0 are affected. Users who are running any pre‑4.15.0 version of the application are at risk if they expose poll URLs or allow public invite links.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity with potential confidentiality impact. The EPSS score is below 1%, suggesting a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can obtain a poll’s identifier from public invite links and then invoke polls.get without authentication. The exploitation requires only a simple HTTP request to the exposed endpoint, with no privileged access or complex prerequisites.

Generated by OpenCVE AI on September 18, 2026 at 05:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Rallly to version 4.15.0 or later, which removes the unauthenticated information disclosure.
  • If an immediate upgrade is not possible, disable public invite links or restrict poll visibility to authenticated users only to limit exposure of the poll URL.
  • Audit current deployments to confirm the poll URLs have not been publicly shared and remove or redact sensitive invitee information from any stored logs or backups.

Generated by OpenCVE AI on September 18, 2026 at 05:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.
Title Rallly before 4.15.0 Information Disclosure via polls.get
First Time appeared Rallly
Rallly rallly
Weaknesses CWE-359
CPEs cpe:2.3:a:rallly:rallly:*:*:*:*:*:*:*:*
Vendors & Products Rallly
Rallly rallly
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:55:53.079Z

Reserved: 2026-09-16T13:34:38.064Z

Link: CVE-2026-92565

cve-icon Vulnrichment

Updated: 2026-09-18T17:55:47.900Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:01.980

Modified: 2026-09-23T17:17:48.983

Link: CVE-2026-92565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:45:03Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor