Description
Use of an incorrectly resolved name or reference in the pinget backend
in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community
catalog contributor to cause an installed application to be correlated
to an unrelated, attacker-controlled catalog package and to execute an
attacker-controlled installer via a crafted catalog package whose
normalized name is contained as a substring within the installed
application name when a user applies the proposed update.
Published: 2026-06-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Devolutions UniGetUI 2026.2.0 and earlier contain an issue where an incorrectly resolved name or reference in the pinget backend can correlate an installed application with an unrelated, attacker‑controlled catalog package. When a user applies the proposed update, the vendor catalog allows the attacker to execute an attacker‑controlled installer whose normalized name is a substring of the installed application name, effectively executing arbitrary code on the local machine. The weakness is a form of input validation failure (CWE‑706), and the primary consequence is unsafe installation of potentially malicious software.

Affected Systems

All installations of Devolutions UniGetUI version 2026.2.0 and prior are vulnerable. The product is Devolutions UniGetUI, and any instance that references the pinget backend for package resolution is at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates considerable severity, but the EPSS score of less than 1% suggests a very low probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to publish a crafted package as a WinGet community catalog contributor; once a user accepts the update, the payload is executed. Because the attack vector relies on community catalog input, it is remotely controllable by the attacker, and the impact is local execution with potential for full compromise of the affected system.

Generated by OpenCVE AI on June 18, 2026 at 18:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of Devolutions UniGetUI (including any release after 2026.2.0 that fixes the name resolution issue).
  • If an immediate update is not possible, disable automatic updates from community catalogs or limit updates to trusted sources only.
  • Monitor the catalog for packages whose names include substrings of existing installed applications and verify the package signature or contents before allowing the installation.

Generated by OpenCVE AI on June 18, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 18 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Title UniGetUI Name Resolution Flaw Enables Malicious Installer Execution

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Description Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a crafted catalog package whose normalized name is contained as a substring within the installed application name when a user applies the proposed update.
Weaknesses CWE-706
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-06-17T19:39:32.170Z

Reserved: 2026-06-02T16:11:22.453Z

Link: CVE-2026-10696

cve-icon Vulnrichment

Updated: 2026-06-17T19:39:24.902Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T18:15:02Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference