Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.

A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. 


This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.

Project Subscriptions

Vendors Products
Algosec Subscribe
Horizon Security Analyzer Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade Horizon Foundation (formerly ASMS suite) to A33.10 (build 310 and above), A33.20 (build 180 and above) and  A33.30 (build 120 and above). https://portal.algosec.com/en/downloads/hotfix_releases


Workaround

No workaround given by the vendor.

History

Tue, 08 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Title Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
First Time appeared Algosec
Algosec horizon Security Analyzer
Weaknesses CWE-266
CPEs cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:linux:*:*:*:*:*
Vendors & Products Algosec
Algosec horizon Security Analyzer
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AlgoSec

Published:

Updated: 2026-09-08T10:44:32.657Z

Reserved: 2026-08-21T04:33:36.370Z

Link: CVE-2026-77654

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T11:17:44.283

Modified: 2026-09-08T11:17:44.283

Link: CVE-2026-77654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses