Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-22306— Critical flaw impacting OZOLS ERP's automatic update channel

Quick assessment

Affected
Ozols Grupa OZOLS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述:代码下载时未进行完整性校验、从不可信的控制域中引入功能,以及对敏感信息进行明文传输的安全漏洞,存在于 Windows 系统上的 Ozols Grupa OZOLS 软件中,其根本原因在于一个已废弃的自动更新域名。受影响的组件包括自动更新通道,具体为:OzolsSQL 客户端更新路径、 SQL Server Agent 作业(@subsystem = N'ActiveScripting')以及 serv_update.vbs 脚本。 该问题影响 OZOLS 1.1.1233 之前的所有版本。

CVSS 10.0 · Critical EPSS 0.15% · P5

Affected Version Matrix 1

VendorProduct Version RangeStatus
Ozols Grupa OZOLS < 1.1.1233 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-22306

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Critical flaw impacting OZOLS ERP's automatic update channel
Source: CVE Program / CVE List V5
Vulnerability Description
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
下载代码缺少完整性检查
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Ozols Grupa OZOLS 0 ~ 1.1.1233 -

II. Public POCs for CVE-2026-22306

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-22306

登录查看更多情报信息。

Security Blog Posts for CVE-2026-22306 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-22306

No comments yet


Leave a comment