CyberRota
← Ana sayfaya dön

CVE-2026-10696

HIGH · CVSS 7.5 EPSS %0.27

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-17T20:16:47.670 · Çekilme zamanı: 2026-06-30T12:25:54.817252+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-10696
Severity
HIGH
CVSS
7.5
EPSS
%0.27

Orijinal NVD Açıklaması

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a crafted catalog package whose normalized name is contained as a substring within the installed application name when a user applies the proposed update.