Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-22306

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-319 Transmisión de información sensible en texto claro
Fecha de publicación:
19/08/2026
Última modificación:
19/08/2026

Descripción

*** Pendiente de traducción *** Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext <br /> transmission of sensitive information vulnerability in Ozols Grupa OZOLS<br /> on Windows caused by an abandoned auto-update domain. Affected<br /> component: the automatic update channel - OzolsSQL client update path, the _update SQL Server Agent job (@subsystem = N&amp;#39;ActiveScripting&amp;#39;) and serv_update.vbs.<br /> <br /> This issue affects OZOLS: before 1.1.1233.

Referencias a soluciones, herramientas e información