{"id":"CVE-2026-77654","title":"Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.\n\nA local user with access to the command line may escalat…","summary":"Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.\n\nA local user with access to the command line may escalat…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber","cwe":["CWE-266"],"vendor":"Algosec","product":"Horizon Security Analyzer","affected":["horizon_security_analyzer A33.10 (up to build 300)","horizon_security_analyzer A33.20 (up to build 170)","horizon_security_analyzer A33.30 (up to build 110)"],"published":"2026-09-08","updated":"2026-09-08","sourceUpdated":"2026-09-08T14:03:48.663","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77654","references":[{"url":"https://techdocs.algosec.com/en/cves/Content/tech-notes/cves/cve-2026-77654.htm","label":"security.vulnerabilities@algosec.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T12:19:17.974612Z"},"cvssSource":"cna","ingestedAt":"2026-09-08T15:33:26.983Z","epss":0.00099,"epssPercentile":0.00897,"slug":"CVE-2026-77654","body":"## Overview\n\nImproper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.\n\nA local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. \n\n\nThis issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}