{"api_version":"1","generated_at":"2026-09-11T14:12:40+00:00","cve":"CVE-2026-77654","urls":{"html":"https://cve.report/CVE-2026-77654","api":"https://cve.report/api/cve/CVE-2026-77654.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77654","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77654"},"summary":{"title":"Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer","description":"Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.\n\nA local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. \n\n\nThis issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.","state":"PUBLISHED","assigner":"AlgoSec","published_at":"2026-09-08 11:17:44","updated_at":"2026-09-08 14:03:48"},"problem_types":["CWE-266","CWE-266 CWE-266 Incorrect privilege assignment"],"metrics":[{"version":"4.0","source":"security.vulnerabilities@algosec.com","type":"Secondary","score":"6.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:L/U:Amber","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:L/U:Amber","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NEGLIGIBLE","Automatable":"YES","Recovery":"USER","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"LOW","providerUrgency":"AMBER"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber","data":{"Automatable":"YES","Recovery":"USER","Safety":"NEGLIGIBLE","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":6.1,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"AMBER","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"LOW"}}],"references":[{"url":"https://techdocs.algosec.com/en/cves/Content/tech-notes/cves/cve-2026-77654.htm","name":"https://techdocs.algosec.com/en/cves/Content/tech-notes/cves/cve-2026-77654.htm","refsource":"security.vulnerabilities@algosec.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77654","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77654","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Algosec","product":"Horizon Security Analyzer","version":"affected A33.10 (up to build 300)","platforms":["Linux","64 bit"]},{"source":"CNA","vendor":"Algosec","product":"Horizon Security Analyzer","version":"affected A33.20 (up to build 170)","platforms":["Linux","64 bit"]},{"source":"CNA","vendor":"Algosec","product":"Horizon Security Analyzer","version":"affected A33.30 (up to build 110)","platforms":["Linux","64 bit"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade Horizon Foundation (formerly ASMS suite) to A33.10 (build 310 and above), A33.20 (build 180 and above) and \nA33.30 (build 120 and above).\n https://portal.algosec.com/en/downloads/hotfix_releases","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Luis Vázquez Castaño - https://www.linkedin.com/in/lvazcas/","lang":"en"},{"source":"CNA","value":"Luis Alberto Pacheco Lorenzo - https://www.linkedin.com/in/lucholapl/","lang":"en"},{"source":"CNA","value":"Siemens Healthineers Red Team","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-77654","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-08T12:19:17.974612Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-08T12:19:26.694Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Linux","64 bit"],"product":"Horizon Security Analyzer","vendor":"Algosec","versions":[{"status":"affected","version":"A33.10 (up to build 300)"},{"status":"affected","version":"A33.20 (up to build 170)"},{"status":"affected","version":"A33.30 (up to build 110)"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:linux:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:algosec:horizon_security_analyzer:a33.10_up_to_build_300_:*:64_bit:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:linux:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:algosec:horizon_security_analyzer:a33.20_up_to_build_170_:*:64_bit:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:linux:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:algosec:horizon_security_analyzer:a33.30_up_to_build_110_:*:64_bit:*:*:*:*:*","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"Luis Vázquez Castaño - https://www.linkedin.com/in/lvazcas/"},{"lang":"en","type":"finder","value":"Luis Alberto Pacheco Lorenzo - https://www.linkedin.com/in/lucholapl/"},{"lang":"en","type":"finder","value":"Siemens Healthineers Red Team"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows&nbsp;Privilege Escalation and Parameter Injection.<br><br>A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.&nbsp;<br><p>This issue affects&nbsp;Horizon Security Analyzer : A33.10, A33.20 and A33.30.<br></p>"}],"value":"Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.\n\nA local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. \n\n\nThis issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30."}],"impacts":[{"capecId":"CAPEC-233","descriptions":[{"lang":"en","value":"CAPEC-233 Privilege Escalation"}]},{"capecId":"CAPEC-137","descriptions":[{"lang":"en","value":"CAPEC-137 Parameter Injection"}]}],"metrics":[{"cvssV4_0":{"Automatable":"YES","Recovery":"USER","Safety":"NEGLIGIBLE","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":6.1,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"AMBER","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"LOW"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-266","description":"CWE-266 Incorrect privilege assignment","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T10:44:32.657Z","orgId":"ca5f073f-8266-4d43-b3e3-6eb0bb18a738","shortName":"AlgoSec"},"references":[{"url":"https://techdocs.algosec.com/en/cves/Content/tech-notes/cves/cve-2026-77654.htm"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Upgrade Horizon Foundation (formerly ASMS suite) to A33.10&nbsp;(build 310 and above), A33.20 (build 180 and above) and&nbsp;\nA33.30 (build 120 and above).<br><a target=\"_blank\" rel=\"nofollow\" href=\"https://portal.algosec.com/en/downloads/hotfix_releases\">https://portal.algosec.com/en/downloads/hotfix_releases</a>"}],"value":"Upgrade Horizon Foundation (formerly ASMS suite) to A33.10 (build 310 and above), A33.20 (build 180 and above) and \nA33.30 (build 120 and above).\n https://portal.algosec.com/en/downloads/hotfix_releases"}],"source":{"discovery":"EXTERNAL"},"title":"Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"ca5f073f-8266-4d43-b3e3-6eb0bb18a738","assignerShortName":"AlgoSec","cveId":"CVE-2026-77654","datePublished":"2026-09-08T10:44:32.657Z","dateReserved":"2026-08-21T04:33:36.370Z","dateUpdated":"2026-09-08T12:19:26.694Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 11:17:44","lastModifiedDate":"2026-09-08 14:03:48","problem_types":["CWE-266","CWE-266 CWE-266 Incorrect privilege assignment"],"metrics":{"cvssMetricV40":[{"source":"security.vulnerabilities@algosec.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:L/U:Amber","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NEGLIGIBLE","Automatable":"YES","Recovery":"USER","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"LOW","providerUrgency":"AMBER"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-08T12:19:17.974612Z","id":"CVE-2026-77654","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77654","Ordinal":"1","Title":"Local Privilege Escalation via Misconfigured Sudoers Entry in Ho","CVE":"CVE-2026-77654","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77654","Ordinal":"1","NoteData":"Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection.\n\nA local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file. \n\n\nThis issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.","Type":"Description","Title":"Local Privilege Escalation via Misconfigured Sudoers Entry in Ho"}]}}}