CVE-2026-77654
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber
- EPSS probability
- 0.10%
- CWE
- CWE-266
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Algosec Horizon Security Analyzer
- Algosec Horizon Security Analyzer
- Algosec Horizon Security Analyzer
Weakness type
Related vulnerabilities
- CVE-2026-15140 — A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP)....
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-85400 — TYPO3 CMS - Missing Authorization in lowlevel commands
- CVE-2026-81792 — WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privilege Escalation vulnerability
- CVE-2026-86516 — elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
- CVE-2026-86512 — java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control
- CVE-2026-86500 — In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update...
- CVE-2026-86482 — In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege...