Description
Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.
Published: 2026-09-08
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper write permissions on the directory C:\\ProgramData\\Maono used by the MaonoAiServices Windows service in Maono Link 3.8.13. A standard user can write arbitrary files to this location, enabling the creation of malicious executables or scripts that are run with elevated privileges when the service processes them. This results in privilege escalation from a normal user account to full administrative rights on the host system.

Affected Systems

Affected products include Maono Link from vendor Maono, specifically version 3.8.13. The issue was fixed in version 4.0.80, so any installations >=4.0.80 are not affected.

Risk and Exploitability

The CVSS score is 8.4, indicating high severity. EPSS is not provided, and the vulnerability is not listed in CISA's KEV catalog. The flaw is local, requiring a user account that has standard privileges on the machine. An attacker could exploit this by creating malicious files under the vulnerable directory. A local administrator or a user maliciously leveraging this can gain full administrative rights, enabling any subsequent actions.

Generated by OpenCVE AI on September 9, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Maono Link version (4.0.80 or newer) to apply the fix that removes the improper write permissions.
  • Verify that the MaonoAiServices Windows service runs with the least privileges and that standard users have no write access to C:\\ProgramData\\Maono.
  • If upgrading cannot be performed immediately, restrict the file system permissions on C:\\ProgramData\\Maono to administrators only, preventing non‑admin users from writing to the directory.

Generated by OpenCVE AI on September 9, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Maono
Maono maono Link
Vendors & Products Maono
Maono maono Link

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.
Title Maono Link local privilege escalation
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Maono Maono Link
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-14T16:58:15.053Z

Reserved: 2026-08-21T14:50:20.105Z

Link: CVE-2026-77827

cve-icon Vulnrichment

Updated: 2026-09-14T16:58:11.504Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:18:39.143

Modified: 2026-09-14T17:17:51.273

Link: CVE-2026-77827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:34Z

Weaknesses
  • CWE-428

    Unquoted Search Path or Element