in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community
catalog contributor to cause an installed application to be correlated
to an unrelated, attacker-controlled catalog package and to execute an
attacker-controlled installer via a crafted catalog package whose
normalized name is contained as a substring within the installed
application name when a user applies the proposed update.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0019 |
|
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions unigetui |
|
| Vendors & Products |
Devolutions
Devolutions unigetui |
Thu, 18 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | UniGetUI Name Resolution Flaw Enables Malicious Installer Execution |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a crafted catalog package whose normalized name is contained as a substring within the installed application name when a user applies the proposed update. | |
| Weaknesses | CWE-706 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-06-17T19:39:32.170Z
Reserved: 2026-06-02T16:11:22.453Z
Link: CVE-2026-10696
Updated: 2026-06-17T19:39:24.902Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:57:12Z