Description
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.

A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. 


This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local user with command‑line access can elevate privileges and inject parameters by abusing a misconfigured sudoers entry that grants a command. The vulnerability stems from improper privilege management (CWE‑266) and allows the local attacker to run privileged commands with manipulated arguments.

Affected Systems

The issue affects Algosec Horizon Security Analyzer versions A33.10, A33.20, and A33.30 on Linux (64‑bit). A33.10 is vulnerable up to build 300, A33.20 up to build 170, and A33.30 up to build 110.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have a local account with command‑line access and rely on the misconfigured sudoers file. Once exploited, the attacker can achieve full root privileges and potentially inject malicious parameters into privileged commands.

Generated by OpenCVE AI on September 8, 2026 at 12:27 UTC.

Remediation

Vendor Solution

Upgrade Horizon Foundation (formerly ASMS suite) to A33.10 (build 310 and above), A33.20 (build 180 and above) and  A33.30 (build 120 and above). https://portal.algosec.com/en/downloads/hotfix_releases


OpenCVE Recommended Actions

  • Apply the vendor‑supplied upgrade to Horizon Foundation build 310 or higher (A33.10), build 180 or higher (A33.20), or build 120 or higher (A33.30).
  • Review and revise the sudoers configuration to remove or restrict the commands that are not necessary for local users, preventing parameter injection.
  • Perform a full audit of local user privileges and sudo rules to ensure no other misconfigurations can enable privilege escalation.

Generated by OpenCVE AI on September 8, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Title Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
First Time appeared Algosec
Algosec horizon Security Analyzer
Weaknesses CWE-266
CPEs cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:linux:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:64_bit:*:*:*:*:*
cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:linux:*:*:*:*:*
Vendors & Products Algosec
Algosec horizon Security Analyzer
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber'}


Subscriptions

Algosec Horizon Security Analyzer
cve-icon MITRE

Status: PUBLISHED

Assigner: AlgoSec

Published:

Updated: 2026-09-08T12:19:26.694Z

Reserved: 2026-08-21T04:33:36.370Z

Link: CVE-2026-77654

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T11:17:44.283

Modified: 2026-09-08T11:17:44.283

Link: CVE-2026-77654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T12:30:17Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment