CVE-2026-22306: Critical flaw impacting OZOLS ERP's automatic update channel
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>update SQL Server Agent job (@subsystem = N'ActiveScripting') and servupdate.vbs.
This issue affects OZOLS: before 1.1.1233.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
OZOLS installations on Windows are affected if they are running a version before 1.1.1233 and use the automatic update channel, including the OzolsSQL client update path, the <db>_update SQL Server Agent job using ActiveScripting, or serv_update.vbs.
What does an attacker need to exploit this issue?
The vulnerability is network-accessible and requires no privileges or user interaction according to the supplied vector. Exploitation is tied to the abandoned domain used by the automatic update channel.
How can I determine whether an environment is exposed?
Check the installed OZOLS version and identify whether the automatic update components are present or active. Specifically review the OzolsSQL client update path, the <db>_update SQL Server Agent job configured with @subsystem = N'ActiveScripting', and serv_update.vbs.
What should be prioritized for remediation?
Update OZOLS to version 1.1.1233 or later. Until the update channel can be remediated, prioritize preventing use of the affected automatic update path and investigate systems that may have retrieved code or transmitted sensitive information through it.