Devolutions UniGetUI < 2026.2.1 Arbitrary Code Execution (DEVO-2026-0019)

high Nessus Plugin ID 322872

Synopsis

The Devolutions UniGetUI instance installed on the remote host is affected by an arbitrary code execution vulnerability.

Description

The version of Devolutions UniGetUI installed on the remote host is 2026.2.0 or earlier. It is, therefore, affected by an arbitrary code execution vulnerability:

- Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a crafted catalog package whose normalized name is contained as a substring within the installed application name when a user applies the proposed update. (CVE-2026-10696)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Devolutions UniGetUI version 2026.2.1 or later.

See Also

https://devolutions.net/security/advisories/DEVO-2026-0019

Plugin Details

Severity: High

ID: 322872

File Name: devolutions_unigetui_DEVO-2026-0019.nasl

Version: 1.2

Type: Local

Agent: windows

Family: Windows

Published: 6/26/2026

Updated: 6/26/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-10696

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/a:devolutions:unigetui

Required KB Items: installed_sw/Devolutions UniGetUI

Patch Publication Date: 6/17/2026

Vulnerability Publication Date: 6/17/2026

Reference Information

CVE: CVE-2026-10696

IAVB: 2026-B-0173