Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Thu, 20 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ozols Grupa
Ozols Grupa ozols |
|
| Vendors & Products |
Ozols Grupa
Ozols Grupa ozols |
Wed, 19 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233. | |
| Title | Critical flaw impacting OZOLS ERP's automatic update channel | |
| Weaknesses | CWE-319 CWE-494 CWE-829 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published: 2026-08-19T19:25:10.530Z
Updated: 2026-08-26T19:29:42.941Z
Reserved: 2026-01-07T09:31:00.562Z
Link: CVE-2026-22306
Updated: 2026-08-26T19:29:35.763Z
Status : Deferred
Published: 2026-08-19T20:17:16.007
Modified: 2026-09-01T21:07:58.980
Link: CVE-2026-22306
No data.