Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-22306: Ozols Grupa OZOLS Windows Code Download Risk
CVE-2026-22306 · published 15 days ago
Summary
A security issue in Ozols Grupa OZOLS affects Windows users. The issue allows malicious code to be downloaded and executed without being checked for authenticity. This could lead to sensitive information being sent without encryption. Affected users should update to version 1.1.1233 or later to fix this issue.
What to do
- Update ozols grupa ozols to version 1.1.1233 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ozols grupa | ozols | < 1.1.1233 |
Original advisory text
Critical flaw impacting OZOLS ERP's automatic update channel
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-319Cleartext Transmission of Sensitive Information
CWE-494Download of Code Without Integrity Check
CWE-829Inclusion of Functionality from Untrusted Control Sphere
Timeline
Published19 Aug 2026
Updated2 Sep 2026
First seen19 Aug 2026
Monitor software like this
Free during beta