A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.
This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Horizon Foundation (formerly ASMS suite) to A33.10 (build 310 and above), A33.20 (build 180 and above) and A33.30 (build 120 and above). https://portal.algosec.com/en/downloads/hotfix_releases
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30. | |
| Title | Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer | |
| First Time appeared |
Algosec
Algosec horizon Security Analyzer |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:64_bit:*:*:*:*:* cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:linux:*:*:*:*:* cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:64_bit:*:*:*:*:* cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:linux:*:*:*:*:* cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:64_bit:*:*:*:*:* cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:linux:*:*:*:*:* |
|
| Vendors & Products |
Algosec
Algosec horizon Security Analyzer |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: AlgoSec
Published:
Updated: 2026-09-08T12:19:26.694Z
Reserved: 2026-08-21T04:33:36.370Z
Link: CVE-2026-77654
Updated: 2026-09-08T12:19:23.133Z
Status : Received
Published: 2026-09-08T11:17:44.283
Modified: 2026-09-08T13:17:26.783
Link: CVE-2026-77654
No data.
OpenCVE Enrichment
Updated: 2026-09-08T12:30:17Z