Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-22306RCE in Ozols SQL via abandoned update domain

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.

View on NVD

Analysis

Ozols SQL en Windows descarga actualizaciones sin cifrado ni verificación de integridad a través de un dominio abandonado. Un atacante puede suplantar el servidor de actualizaciones para ejecutar código arbitrario en el sistema y bases de datos afectadas mediante el componente OzolsSQL.

Relevant roles

WindowsSqlBackendCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-319CWE-494CWE-829

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.

Published: 8/19/2026, 8:17:16 PM
Last modified: 8/19/2026, 8:17:16 PM

References

HomeEventsBlogResourcesCoursesTeam