# CVE-2026-77654

## Summary

- **CVE ID:** CVE-2026-77654
- **Severity:** MEDIUM
- **CVSS Score:** 6.1 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber)
- **CWE:** CWE-266
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.

A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. 


This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.

## Affected Products

- Algosec — Horizon Security Analyzer (A33.10 (up to build 300))
- Algosec — Horizon Security Analyzer (A33.20 (up to build 170))
- Algosec — Horizon Security Analyzer (A33.30 (up to build 110))

## References

- [CNA](https://techdocs.algosec.com/en/cves/Content/tech-notes/cves/cve-2026-77654.htm)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 0.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._