Description
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.

This issue affects OZOLS: before 1.1.1233.
Published: 2026-08-19
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to supply malicious code through an abandoned auto‑update domain used by OZOLS ERP. The application downloads executable scripts without performing an integrity check, then runs them with the SQL Server Agent using ActiveScripting. The result is unchecked inclusion of untrusted functionality and cleartext transmission of sensitive data. An attacker who can influence the auto‑update channel can execute arbitrary code on the host, potentially compromising confidentiality, integrity, and availability of the system.

Affected Systems

Ozols Grupa’s OZOLS ERP product, running on Windows, is vulnerable for all versions before 1.1.1233. The affected components are the automatic update channel – the OzolsSQL client update path, the database server job named <db>_update that uses ActiveScripting, and the serv_update.vbs script.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. While an EPSS score is not available, the absence of a KEV listing does not lower the risk; the high severity and the fact that the flaw enables remote code execution through a network‑visible update path mean that exploitation is likely if an attacker can host or redirect updates. The attack vector is inferred to be remote network access to the abandoned update domain, which the application contacts without authentication or integrity validation.

Generated by OpenCVE AI on August 20, 2026 at 12:26 UTC.

Remediation

Vendor Workaround

* disable or delete the <db>_update SQL Server Agent job and remove serv_update.vbs; * block outbound access from database servers and workstations to its2.lv / www2.its2.lv, and restrict arbitrary outbound HTTP from those hosts; * disable xp_cmdshell on affected SQL Server instances; * run the SQL Server service under a least-privilege account; * inspect the sprg table for unexpected version increments or archive contents.


OpenCVE Recommended Actions

  • Disable or delete the <db>_update SQL Server Agent job and remove the serv_update.vbs script.
  • Block outbound connections from the database servers and workstations to its2.lv / www2.its2.lv and restrict arbitrary outbound HTTP traffic.
  • Disable xp_cmdshell on the affected SQL Server instances.
  • Run the SQL Server service using a least‑privilege account.
  • Inspect the sprg table for unexpected version increments or archive contents.

Generated by OpenCVE AI on August 20, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Ozols Grupa
Ozols Grupa ozols
Vendors & Products Ozols Grupa
Ozols Grupa ozols

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
Title Critical flaw impacting OZOLS ERP's automatic update channel
Weaknesses CWE-319
CWE-494
CWE-829
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Ozols Grupa Ozols
cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-08-26T19:29:42.941Z

Reserved: 2026-01-07T09:31:00.562Z

Link: CVE-2026-22306

cve-icon Vulnrichment

Updated: 2026-08-26T19:29:35.763Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T20:17:16.007

Modified: 2026-09-01T21:07:58.980

Link: CVE-2026-22306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:30:05Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information

  • CWE-494

    Download of Code Without Integrity Check

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere