Junglewise Threat Intelligence

CVE-2026-10696: Devolutions UniGetUI incorrect package correlation in pinget backend

CVE-2026-10696 · Severity: high · CVSS 7.5 · Published 2026-06-17

Vendors: Devolutions.

Executive brief

UniGetUI is a tool used to manage, install, and update Windows software packages. A vulnerability in how the tool identifies software updates allows a malicious contributor to a public software catalog to trick the system into replacing a legitimate application with a malicious one. If a user accepts a proposed update for an affected application, the tool will execute an attacker-controlled installer, potentially leading to a full system compromise.

Technical details

A vulnerability exists in the pinget backend of Devolutions UniGetUI (version 2026.2.0 and earlier) due to the use of an incorrectly resolved name or reference (CWE-706). The flaw allows a WinGet community catalog contributor to craft a package whose normalized name is a substring of a legitimate installed application's name. This causes UniGetUI to incorrectly correlate the installed application with the attacker's malicious package. When a user attempts to apply what appears to be a legitimate update, the application instead executes the attacker-controlled installer. This vulnerability is remediated in version 2026.2.1.

Affected products

  • Devolutions UniGetUI 2026.2.0 and earlier

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory
  • 2026-06-17: patched: Fixed in version 2026.2.1

References