Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://offseq.com/en/research/ozols-cve-2026-22306 |
|
History
Thu, 20 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ozols Grupa
Ozols Grupa ozols |
|
| Vendors & Products |
Ozols Grupa
Ozols Grupa ozols |
Wed, 19 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233. | |
| Title | Critical flaw impacting OZOLS ERP's automatic update channel | |
| Weaknesses | CWE-319 CWE-494 CWE-829 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-08-19T19:25:10.530Z
Reserved: 2026-01-07T09:31:00.562Z
Link: CVE-2026-22306
No data.
Status : Received
Published: 2026-08-19T20:17:16.007
Modified: 2026-08-19T20:17:16.007
Link: CVE-2026-22306
No data.
OpenCVE Enrichment
Updated: 2026-08-20T12:30:05Z