CVE-2026-22306
10.0Ozols Grupa · OZOLS
The OZOLS software is vulnerable to code execution via an abandoned auto-update domain, allowing for insecure code download and cleartext transmission of sensitive data.
Executive summary
OZOLS software contains a critical supply chain vulnerability due to an abandoned update domain, enabling unauthenticated remote code execution.
Vulnerability
The application uses an abandoned domain for its automatic update channel, which lacks integrity checks. An attacker can intercept this channel to deliver malicious updates that are executed with high privileges by the SQL Server Agent or the client update process.
Business impact
With a CVSS score of 10.0, this vulnerability allows for the total compromise of systems running the OZOLS software. The ability to push unauthorized code via the update mechanism poses a systemic risk to all internal systems that rely on this software for database and server management.
Remediation
Immediate Action: Update the OZOLS software to version 1.1.1233 or higher to resolve the insecure update channel configuration.
Proactive Monitoring: Audit logs for the SQL Server Agent and the OzolsSQL client update path for any unexpected script execution or connection attempts to unauthorized domains.
Compensating Controls: Block outbound traffic from the application server to the compromised domain and ensure the software is restricted to a segmented network environment.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability is highly severe because it exploits a trusted update mechanism. Organizations should update the software immediately and consider auditing all recent update activities to ensure no malicious code was introduced prior to patching.