VYPR
High severity7.5NVD Advisory· Published Jun 17, 2026· Updated Jun 24, 2026

CVE-2026-10696

CVE-2026-10696

Description

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a crafted catalog package whose normalized name is contained as a substring within the installed application name when a user applies the proposed update.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:devolutions:unigetui:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:devolutions:unigetui:*:*:*:*:*:*:*:*range: <2026.2.1.0
    • (no CPE)range: <=2026.2.0

Patches

Vulnerability mechanics

References

1

News mentions

1