PT-2026-45879 · Alf.Io · Alf.Io

·

CVE-2026-35482

·

Published

2026-06-02

·

Updated

2026-08-12

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions alf.io versions prior to 2.0-M5-2606
Description A sandbox escape issue exists in the extension script engine of alf.io, an open source ticket reservation system. An authenticated administrator can execute arbitrary operating system commands on the server. The system uses a sandboxed Rhino environment to execute restricted JavaScript; however, the use of an unguarded injected Java object returnClass combined with an incomplete AST (Abstract Syntax Tree) blocklist allows the sandbox to be bypassed via Java reflection. This flaw can be triggered through the Extensions API.
Recommendations Update alf.io to version 2.0-M5-2606.

Exploit

Fix

RCE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35482
GHSA-3W8F-MCF6-CM7H

Affected Products

Alf.Io