Description
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.

This issue affects OZOLS: before 1.1.1233.
Published: 2026-08-19
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

* disable or delete the <db>_update SQL Server Agent job and remove serv_update.vbs; * block outbound access from database servers and workstations to its2.lv / www2.its2.lv, and restrict arbitrary outbound HTTP from those hosts; * disable xp_cmdshell on affected SQL Server instances; * run the SQL Server service under a least-privilege account; * inspect the sprg table for unexpected version increments or archive contents.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Ozols Grupa
Ozols Grupa ozols
Vendors & Products Ozols Grupa
Ozols Grupa ozols

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
Title Critical flaw impacting OZOLS ERP's automatic update channel
Weaknesses CWE-319
CWE-494
CWE-829
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Ozols Grupa Ozols
cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-08-26T19:29:42.941Z

Reserved: 2026-01-07T09:31:00.562Z

Link: CVE-2026-22306

cve-icon Vulnrichment

Updated: 2026-08-26T19:29:35.763Z

cve-icon NVD

Status : Received

Published: 2026-08-19T20:17:16.007

Modified: 2026-08-26T20:17:10.923

Link: CVE-2026-22306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:30:05Z

Weaknesses