Junglewise Threat Intelligence

CVE-2026-77827: Maono Link local privilege escalation in MaonoAiServices

CVE-2026-77827 · Severity: high · CVSS 7.1 · Published 2026-09-08

Executive brief

Maono Link is audio software for Windows that includes a system service called MaonoAiServices. The service is susceptible to privilege escalation, allowing an attacker with a standard user account to gain administrator-level access by exploiting improper file permissions on the application's data directory. Successful exploitation would allow an attacker to run arbitrary code with system privileges, potentially compromising the entire computer and any data stored on it.

Technical details

The vulnerability is a privilege escalation flaw (CWE-428: unquoted search path/element) in the MaonoAiServices Windows service running in Maono Link 3.8.13. The root cause is improper write privileges on the 'C:\ProgramData\Maono' directory, allowing standard user accounts to modify files or registry entries that the service reads during execution. Attack requires local system access and valid user credentials (no network exposure); the service automatically loads compromised files at runtime. An attacker can inject malicious code that executes with system privileges, achieving arbitrary code execution. The vulnerability is fixed in version 4.0.80.

Affected products

  • Maono Maono Link 3.8.13 to 4.0.79

Timeline

  • 2026-09-08: disclosed
  • 2026-09-04: patched: Version 4.0.80 released with fix

References