Junglewise Threat Intelligence

CVE-2026-35482: alf.io sandbox escape in extension script engine

CVE-2026-35482 · Severity: high · CVSS 8 · Published 2026-06-02

Technologies: Alfio-Event Alf.Io. Vendors: Alf.Io.

Executive brief

alf.io is an open-source ticket reservation system used for managing events like conferences and workshops. A security flaw in the system's extension engine allows an administrator to bypass security restrictions and execute unauthorized commands on the underlying server. This could lead to a complete takeover of the server, resulting in the theft of attendee data, service outages, or the use of the server for further attacks.

Technical details

A sandbox escape exists in the alf.io extension script engine due to the improper exposure of Java objects within the Rhino JavaScript environment. Specifically, the `ScriptingExecutionService.executeScriptFinally()` method injects an unrestricted `java.lang.Class` object (named `returnClass`) into the script scope. While the system attempts to use AST validation and a class whitelist to restrict script capabilities, an attacker can use `returnClass.forName()` and Java reflection to bypass these controls. By reflecting into `java.lang.Runtime`, an authenticated administrator can execute arbitrary OS commands. The vulnerability is triggered when a malicious extension script is saved and subsequently executed by a system event. This issue is patched in version 2.0-M5-2606.

Affected products

  • alfio-event alf.io < 2.0-M5-2606

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory
  • 2026-06-02: patched

References

Related threats