CVE-2026-77827: Maono Link local privilege escalation
Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Maono Linkto a version that resolves this vulnerability.Fixed in 4.0.80
Event History
Frequently Asked Questions
Who is exposed to this issue?
Windows systems running Maono Link 3.8.13 are exposed if a standard local user account can exploit the improper write permissions in C:\ProgramData\Maono. Exploitation is local and requires low-privileged access to the system.
What does an attacker need to exploit it?
An attacker needs access to a local standard user account. No user interaction is required, and the vulnerability can be used to elevate privileges through the MaonoAiServices Windows service.
What version fixes the issue?
The issue is fixed in Maono Link 4.0.80.
How can I check whether a system may be affected?
Check whether Maono Link 3.8.13 is installed and inspect permissions on C:\ProgramData\Maono. Systems where standard users have improper write access to that directory may be vulnerable.