CVE-2026-77654 PUBLISHED

Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer

Assigner: AlgoSec
Reserved: 21.08.2026 Published: 08.09.2026 Updated: 08.09.2026

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.

A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. 

This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber
CVSS Score: 6.1

Product Status

Vendor Algosec
Product Horizon Security Analyzer
Versions Default: unaffected
  • Version A33.10 (up to build 300) is affected
  • Version A33.20 (up to build 170) is affected
  • Version A33.30 (up to build 110) is affected

Solutions

Upgrade Horizon Foundation (formerly ASMS suite) to A33.10 (build 310 and above), A33.20 (build 180 and above) and  A33.30 (build 120 and above). https://portal.algosec.com/en/downloads/hotfix_releases

Credits

  • Luis Vázquez Castaño - https://www.linkedin.com/in/lvazcas/ finder
  • Luis Alberto Pacheco Lorenzo - https://www.linkedin.com/in/lucholapl/ finder
  • Siemens Healthineers Red Team finder

References

Problem Types

  • CWE-266 Incorrect privilege assignment CWE

Impacts

  • CAPEC-233 Privilege Escalation
  • CAPEC-137 Parameter Injection