CVE-2026-10696Disclosure(devolutions / unigetui)
LOWCVSS 7.5 · HIGHSignal is active with 1 mentions in latest observed window
Immediate actions
- Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a crafted catalog package whose normalized name is contained as a substring within the installed application name when a user applies the proposed update.
Sources & remediation
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- unigetui
Threat summary
- 2 mentions across 2 observed days
- Momentum state: stable
What's happening
- Technical details provided in 2 signals
- Disclosure: 2 classified signals
- Peaked 1d ago at 1 mentions (2026-06-17); latest day: 1
- 2 total mentions across 2 days
Affected systems
Deep dive
Activity timeline2 mentions / 2d
Signal classification1 categories
Referenced assets2 URLs
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | devolutions | unigetui | - | - | - |
