CVE-2026-77654

Summary

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.

A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. 

This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.

Affected Software

VendorProductVersion RangeStatus
AlgosecHorizon Security AnalyzerA33.10 (up to build 300)affected
AlgosecHorizon Security AnalyzerA33.20 (up to build 170)affected
AlgosecHorizon Security AnalyzerA33.30 (up to build 110)affected

Weaknesses

  • CWE-266: CWE-266 Incorrect privilege assignment

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References