Security & compliance
Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0033
UniGetUI is affected by multiple vulnerabilities.
Affected Products
Change Log
Initial publication - 2026-09-16
OS command injection via package version and id fields in the PowerShell package managers
8.4 High - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
OS command injection in the PowerShell package manager version handling allows an attacker to execute arbitrary commands with the privileges of the user running UniGetUI via a crafted package bundle whose version field contains a statement separator, once the victim imports and installs the package.
CVE(s)
CVE-2026-92219
Remediation and Workarounds
Upgrade to Devolutions UniGetUI 2026.3.0 or higher.
Path traversal in settings import allows arbitrary file write
6.7 Medium - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Path traversal in the settings import feature allows an attacker to write arbitrary files to a user-writable location via a crafted settings key containing directory traversal sequences, achieving persistence and code execution in the context of the victim user.
CVE(s)
CVE-2026-92556
Remediation and Workarounds
Upgrade to UniGetUI 2026.3.0 or higher.
Credits
Yusuf Bahbah