Sandbox Escape Vulnerability in alf.io Ticket Reservation System
CVE-2026-35482

8HIGH

Key Information:

Status
Vendor
CVE Published:
2 June 2026

What is CVE-2026-35482?

CVE-2026-35482 is a serious vulnerability found in the alf.io ticket reservation system, which is an open-source platform utilized for managing ticket sales for various events such as conferences, trade shows, and workshops. This vulnerability arises from a flaw in the sandboxing mechanism of the alf.io extension script engine, allowing an authenticated administrator to escape the sandbox environment. Specifically, the vulnerability allows for the execution of arbitrary operating system commands on the server through a combination of an unguarded injected Java object and inadequate safeguards in the abstract syntax tree (AST) blocklist. This could pose a critical risk to organizations employing alf.io, as it enables unauthorized execution of commands that could compromise server integrity and security.

Potential impact of CVE-2026-35482

  1. Arbitrary Command Execution: The primary risk associated with CVE-2026-35482 is that it allows authenticated users with administrative access to run arbitrary commands on the server. This could lead to unauthorized control over the server, potentially resulting in data breaches or loss.

  2. System Compromise: Organizations affected by this vulnerability could experience significant disruptions as attackers exploit the flaw to compromise the system, leading to the installation of malware, data exfiltration, or manipulation of configurations that affect the availability and integrity of services.

  3. Reputational Damage: The exploitation of this vulnerability could not only lead to financial impacts due to operational disturbances or regulatory penalties but also result in substantial reputational damage to organizations relying on alf.io for event management, undermining user trust and client relationships.

Affected Version(s)

alf.io < 2.0-M5-2606

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.