Privilege Escalation in Horizon Security Analyzer by AlgoSec
CVE-2026-77654
6.1MEDIUM
What is CVE-2026-77654?
An improper privilege management vulnerability exists in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) for Linux 64-bit systems. This flaw permits a local user with command line access to escalate privileges by manipulating parameters within commands listed in the sudoers file. Consequently, unauthorized operations could be performed, potentially compromising the integrity and security of the affected systems. This issue primarily affects versions A33.10, A33.20, and A33.30.
Affected Version(s)
Horizon Security Analyzer Linux A33.10 (up to build 300)
Horizon Security Analyzer Linux A33.20 (up to build 170)
Horizon Security Analyzer Linux A33.30 (up to build 110)
References
CVSS V4
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Luis Vázquez Castaño - https://www.linkedin.com/in/lvazcas/
Luis Alberto Pacheco Lorenzo - https://www.linkedin.com/in/lucholapl/
Siemens Healthineers Red Team
