A critical vulnerability (CVE-2026-22306) has been identified in Ozols Grupa OZOLS, impacting versions prior to 1.1.1233. The flaw arises from the lack of integrity checks during code downloads, allowing untrusted updates to be executed. This affects the automatic update channel (OzolsSQL client update path), the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting'), and serv_update.vbs. Attackers can exploit this to inject malicious code, leading to remote code execution. The CVSS score of 10.0 reflects the high severity. Organizations using affected versions of Ozols Grupa OZOLS should immediately apply the latest security patches and disable the automatic update feature until updates are applied. Additionally, network segmentation and monitoring for unusual activity are recommended to mitigate potential exploitation.
CRITICAL
CVSS 10.0
CVE-2026-22306
2026-08-28
Critical Vulnerability in Ozols Grupa OZOLS (CVE-2026-22306)
A critical vulnerability (CVE-2026-22306) allows attackers to execute arbitrary code via untrusted updates in Ozols Grupa OZOLS, affecting versions before 1.1.1233. CVSS score: 10.0.