PT-2026-45879 · Alf.Io · Alf.Io

·

CVE-2026-35482

·

Published

2026-06-02

·

Updated

2026-07-07

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions alf.io versions prior to 2.0-M5-2606
Description A sandbox escape issue exists in the extension script engine of alf.io, an open source ticket reservation system. An authenticated administrator can execute arbitrary operating system commands on the server. The system uses a sandboxed Rhino environment to execute restricted JavaScript; however, an incomplete AST (Abstract Syntax Tree) blocklist and an unguarded injected Java object returnClass allow the sandbox to be bypassed using Java reflection. This flaw can be triggered through the Extensions API.
Recommendations Update to version 2.0-M5-2606.

Exploit

Fix

RCE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35482
GHSA-3W8F-MCF6-CM7H

Affected Products

Alf.Io