CVE-2026-22306: Critical flaw impacting OZOLS ERP's automatic update channel

Published Aug 19, 2026
·
Updated

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>update SQL Server Agent job (@subsystem = N'ActiveScripting') and servupdate.vbs.

This issue affects OZOLS: before 1.1.1233.

Affected Software

1 affected component
OZOLS<1.1.1233

Event History

Aug 19, 2026
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

OZOLS installations on Windows are affected if they are running a version before 1.1.1233 and use the automatic update channel, including the OzolsSQL client update path, the <db>_update SQL Server Agent job using ActiveScripting, or serv_update.vbs.

2

What does an attacker need to exploit this issue?

The vulnerability is network-accessible and requires no privileges or user interaction according to the supplied vector. Exploitation is tied to the abandoned domain used by the automatic update channel.

3

How can I determine whether an environment is exposed?

Check the installed OZOLS version and identify whether the automatic update components are present or active. Specifically review the OzolsSQL client update path, the <db>_update SQL Server Agent job configured with @subsystem = N'ActiveScripting', and serv_update.vbs.

4

What should be prioritized for remediation?

Update OZOLS to version 1.1.1233 or later. Until the update channel can be remediated, prioritize preventing use of the affected automatic update path and investigate systems that may have retrieved code or transmitted sensitive information through it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203