Critical flaw impacting OZOLS ERP's automatic update channel
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 10epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
Ozols Grupa · OZOLSpublic PoCs found — 1
cve_referenceoffseq.com/en/research/ozols-cve-2026-22306/#s-04unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.