CVE-2026-77827 PUBLISHED

Maono Link local privilege escalation

Assigner: cisa-cg
Reserved: 21.08.2026 Published: 08.09.2026 Updated: 08.09.2026

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor Maono
Product Maono Link
Versions Default: affected
  • affected from 3.8.13 to 4.0.80 (excl.)
  • Version 4.0.80 is unaffected

Credits

  • Shravan Kumar Sheri

References

Problem Types

  • CWE-428 Unquoted Search Path or Element CWE