Description
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.

A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. 


This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade Horizon Foundation (formerly ASMS suite) to A33.10 (build 310 and above), A33.20 (build 180 and above) and  A33.30 (build 120 and above). https://portal.algosec.com/en/downloads/hotfix_releases

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Title Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
First Time appeared Algosec
Algosec horizon Security Analyzer
Weaknesses CWE-266
CPEs cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:linux:*:*:*:*:*
Vendors & Products Algosec
Algosec horizon Security Analyzer
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber'}


Subscriptions

Algosec Horizon Security Analyzer
cve-icon MITRE

Status: PUBLISHED

Assigner: AlgoSec

Published:

Updated: 2026-09-08T12:19:26.694Z

Reserved: 2026-08-21T04:33:36.370Z

Link: CVE-2026-77654

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T11:17:44.283

Modified: 2026-09-08T11:17:44.283

Link: CVE-2026-77654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T12:30:17Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment