MENU PRINCIPALE

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0033

UniGetUI is affected by multiple vulnerabilities.

Affected Products

UniGetUI
2026.2.7 and earlier

Change Log

Initial publication - 2026-09-16

OS command injection via package version and id fields in the PowerShell package managers

8.4 High - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

OS command injection in the PowerShell package manager version handling allows an attacker to execute arbitrary commands with the privileges of the user running UniGetUI via a crafted package bundle whose version field contains a statement separator, once the victim imports and installs the package.

CVE(s)

CVE-2026-92219

Remediation and Workarounds

Upgrade to Devolutions UniGetUI 2026.3.0 or higher.

Path traversal in settings import allows arbitrary file write

6.7 Medium - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Path traversal in the settings import feature allows an attacker to write arbitrary files to a user-writable location via a crafted settings key containing directory traversal sequences, achieving persistence and code execution in the context of the victim user.

CVE(s)

CVE-2026-92556

Remediation and Workarounds

Upgrade to UniGetUI 2026.3.0 or higher.

Credits

Yusuf Bahbah