CVE-2026-22306RCE in Ozols SQL via abandoned update domain
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
View on NVDAnalysis
Ozols SQL en Windows descarga actualizaciones sin cifrado ni verificación de integridad a través de un dominio abandonado. Un atacante puede suplantar el servidor de actualizaciones para ejecutar código arbitrario en el sistema y bases de datos afectadas mediante el componente OzolsSQL.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-319CWE-494CWE-829EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.