CVE-2026-77827
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Summary
Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Maono | Maono Link | 3.8.13 < 4.0.80 | affected |
| Maono | Maono Link | 4.0.80 | unaffected |
Weaknesses
- CWE-428: CWE-428 Unquoted Search Path or Element
References
- https://www.maono.com/products/maono-link-software
- https://www.cve.org/CVERecord?id=CVE-2026-77827
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-251-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.