CVE-2026-35482
alf.io Administrator Sandbox Escape Vulnerability Allows OS Command Execution.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A sandbox escape vulnerability in alf.io's extension script engine allows an authenticated administrator to execute arbitrary operating system commands on the server. This could impact the confidentiality, integrity, and availability of the server.