CVE-2026-22306 PUBLISHED

Critical flaw impacting OZOLS ERP's automatic update channel

Assigner: ENISA
Reserved: 07.01.2026 Published: 19.08.2026 Updated: 19.08.2026

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.

This issue affects OZOLS: before 1.1.1233.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Ozols Grupa
Product OZOLS
Versions Default: unaffected
  • affected from 0 to 1.1.1233 (excl.)

Workarounds

  • disable or delete the <db>_update SQL Server Agent job and remove serv_update.vbs;
  • block outbound access from database servers and workstations to its2.lv / www2.its2.lv, and restrict arbitrary outbound HTTP from those hosts;
  • disable xp_cmdshell on affected SQL Server instances;
  • run the SQL Server service under a least-privilege account;
  • inspect the sprg table for unexpected version increments or archive contents.

Credits

  • Nils Putniņš, OffSeq (SIA SEQ) finder
  • CERT.LV coordinator

References

Problem Types

  • CWE-494 Download of code without integrity check CWE
  • CWE-829 Inclusion of functionality from untrusted control sphere CWE
  • CWE-319 Cleartext transmission of sensitive information CWE

Impacts

  • CAPEC-186 Malicious Software Update
  • CAPEC-187 Malicious Automated Software Update via Redirection