Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-10696

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
17/06/2026
Última modificación:
24/06/2026

Descripción

*** Pendiente de traducción *** Use of an incorrectly resolved name or reference in the pinget backend <br /> in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community <br /> catalog contributor to cause an installed application to be correlated <br /> to an unrelated, attacker-controlled catalog package and to execute an <br /> attacker-controlled installer via a crafted catalog package whose <br /> normalized name is contained as a substring within the installed <br /> application name when a user applies the proposed update.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:devolutions:unigetui:*:*:*:*:*:*:*:* 2026.2.1.0 (excluyendo)


Referencias a soluciones, herramientas e información