Sceawere
Vulnerability Detail
CVE-2026-22306UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OZOLS Insecure Update Vulnerabilities
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 4h ago
- Vendor
- Ozols Grupa
- Product
- OZOLS
- Attack Type
- CWE-494 Download of code without integrity check
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-08-19T20:17:16.007Z",
"pubdate": "2026-08-19T20:17:16.007Z",
"executiveSummary": "Ozols Grupa OZOLS on Windows contains critical vulnerabilities involving the download of code without integrity check, the inclusion of functionality from an untrusted control sphere, and the cleartext transmission of sensitive information. These security flaws stem from an abandoned auto-update domain utilized by the application.\nThe affected component is the automatic update channel, specifically involving the OzolsSQL client update path, the <db>_update SQL Server Agent job utilizing @subsystem = N'ActiveScripting', and the serv_update.vbs script. This issue affects OZOLS versions before 1.1.1233.\nThe combination of these weaknesses introduces significant risk implications, allowing an attacker to exploit the abandoned domain to intercept or spoof update requests, inject malicious payloads, and execute arbitrary code within the context of the affected SQL Server or client systems. Exploitation can lead to full system compromise, data exfiltration due to cleartext transmission, and unauthorized manipulation of database operations.\nAttacker capabilities include potential Man-in-the-Middle (MitM) positioning or domain takeover of the abandoned update infrastructure to deliver malicious payloads without cryptographic verification or integrity checks.",
"technicalDetails": "The root cause of the vulnerability resides in the architectural design of the OZOLS automatic update mechanism, which relies on an abandoned auto-update domain. This missing infrastructure control allows external entities to potentially claim the domain or intercept traffic directed to it.\nThe vulnerable component comprises the automatic update channel, specifically the OzolsSQL client update path, the <db>_update SQL Server Agent job executing with @subsystem = N'ActiveScripting', and the serv_update.vbs file. Affected versions include all iterations of OZOLS prior to version 1.1.1233.\nThe exploitation method leverages insecure operational practices where updates are transmitted in cleartext without integrity checks or cryptographic validation. Because the update domain is abandoned, an attacker can exploit the trust relationship established by the client application during the update check.\nThe attack flow proceeds as follows: First, the client initiates the automated update sequence via the OzolsSQL client update path or the scheduled <db>_update SQL Server Agent job running the serv_update.vbs script. Second, because communication occurs over cleartext protocols and points to the abandoned auto-update domain, network traffic can be intercepted, or the domain can be registered by a malicious actor. Third, the application downloads update packages or scripts containing functionality from an untrusted control sphere. Fourth, the system executes the downloaded code—such as active scripting payloads via the SQL Server Agent job—without performing any integrity checks, cryptographic signature validation, or authenticity verification.\nThe post-exploitation impact includes arbitrary code execution with the privileges of the SQL Server Agent or the executing user account, potential database compromise, unauthorized access to sensitive cleartext data transmitted across the update channel, and complete system takeover."
}