Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-22306RCE en Ozols SQL por dominio de actualización abandonado

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.

Ver en NVD

Análisis

Ozols SQL en Windows descarga actualizaciones sin cifrado ni verificación de integridad a través de un dominio abandonado. Un atacante puede suplantar el servidor de actualizaciones para ejecutar código arbitrario en el sistema y bases de datos afectadas mediante el componente OzolsSQL.

Roles relevantes

WindowsSqlBackendCyberSecurity

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-319CWE-494CWE-829

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.

Publicada: 19/8/2026, 20:17:16
Última modificación: 19/8/2026, 20:17:16

Referencias

InicioEventosBlogRecursosCursosEquipo