CVE-2026-22306
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ozols Grupa | OZOLS | 0 < 1.1.1233 | affected |
Weaknesses
- CWE-494: CWE-494 Download of code without integrity check
- CWE-829: CWE-829 Inclusion of functionality from untrusted control sphere
- CWE-319: CWE-319 Cleartext transmission of sensitive information
Workarounds
- disable or delete the <db>_update SQL Server Agent job and remove serv_update.vbs;
- block outbound access from database servers and workstations to its2.lv / www2.its2.lv, and restrict arbitrary outbound HTTP from those hosts;
- disable xp_cmdshell on affected SQL Server instances;
- run the SQL Server service under a least-privilege account;
- inspect the sprg table for unexpected version increments or archive contents.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.