Executive brief
UniGetUI is a tool used to manage, install, and update Windows software packages. A vulnerability in how the tool identifies software updates allows a malicious contributor to a public software catalog to trick the system into replacing a legitimate application with a malicious one. If a user accepts a proposed update for an affected application, the tool will execute an attacker-controlled installer, potentially leading to a full system compromise.
Technical details
A vulnerability exists in the pinget backend of Devolutions UniGetUI (version 2026.2.0 and earlier) due to the use of an incorrectly resolved name or reference (CWE-706). The flaw allows a WinGet community catalog contributor to craft a package whose normalized name is a substring of a legitimate installed application's name. This causes UniGetUI to incorrectly correlate the installed application with the attacker's malicious package. When a user attempts to apply what appears to be a legitimate update, the application instead executes the attacker-controlled installer. This vulnerability is remediated in version 2026.2.1.
Affected products
- Devolutions UniGetUI 2026.2.0 and earlier
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-17: patched: Fixed in version 2026.2.1