Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
History

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Title Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
First Time appeared Algosec
Algosec horizon Security Analyzer
Weaknesses CWE-266
CPEs cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:linux:*:*:*:*:*
Vendors & Products Algosec
Algosec horizon Security Analyzer
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AlgoSec

Published: 2026-09-08T10:44:32.657Z

Updated: 2026-09-08T12:19:26.694Z

Reserved: 2026-08-21T04:33:36.370Z

Link: CVE-2026-77654

cve-icon Vulnrichment

Updated: 2026-09-08T12:19:23.133Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T11:17:44.283

Modified: 2026-09-08T14:03:48.663

Link: CVE-2026-77654

cve-icon Redhat

No data.