Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77654— Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer

Quick assessment

Affected
Algosec Horizon Security Analyzer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述的中文翻译: Horizon 安全分析器(原 AlgoSec 防火墙分析器)在 Linux 64 位系统上存在“权限管理不当”漏洞,可导致权限提升和参数注入。 本地用户若拥有命令行访问权限,可通过滥用 sudoers 文件中已授权命令的参数,从而实现权限提升。 受影响的版本: Horizon Security Analyzer 版本 A33.10、A33.20 和 A33.30。

CVSS 6.1 · Medium EPSS 0.10% · P1

Affected Version Matrix 3

VendorProduct Version RangeStatus
Algosec Horizon Security Analyzer A33.10 (up to build 300) affected
A33.20 (up to build 170) affected
A33.30 (up to build 110) affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77654

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Horizon Security Analyzer : A33.10, A33.20 and A33.30.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Algosec Horizon Security Analyzer A33.10 (up to build 300) -

II. Public POCs for CVE-2026-77654

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77654

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77654 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77654

No comments yet


Leave a comment