{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-22306",
        "assignerOrgId": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
        "state": "PUBLISHED",
        "assignerShortName": "ENISA",
        "dateReserved": "2026-01-07T09:31:00.562Z",
        "datePublished": "2026-08-19T19:25:10.530Z",
        "dateUpdated": "2026-08-26T19:29:42.941Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
                "shortName": "ENISA",
                "dateUpdated": "2026-08-19T19:25:10.530Z"
            },
            "title": "Critical flaw impacting OZOLS ERP's automatic update channel",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-494",
                            "description": "CWE-494 Download of code without integrity check",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-829",
                            "description": "CWE-829 Inclusion of functionality from untrusted control sphere",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-319",
                            "description": "CWE-319 Cleartext transmission of sensitive information",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-186",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-186 Malicious Software Update"
                        }
                    ]
                },
                {
                    "capecId": "CAPEC-187",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-187 Malicious Automated Software Update via Redirection"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Ozols Grupa",
                    "product": "OZOLS",
                    "platforms": [
                        "Windows"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "1.1.1233",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext \ntransmission of sensitive information vulnerability in Ozols Grupa OZOLS\n on Windows caused by an abandoned auto-update domain. Affected\ncomponent: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.\n\nThis issue affects OZOLS: before 1.1.1233.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext \ntransmission of sensitive information vulnerability in Ozols Grupa OZOLS\n on Windows caused by an&nbsp;<span>abandoned auto-update domain</span>.&nbsp;<span>Affected\ncomponent: the automatic update channel -&nbsp;</span><span>OzolsSQL</span><span>&nbsp;client update path, the&nbsp;</span><span>&lt;db&gt;_update</span><span>&nbsp;SQL Server Agent job (</span><span>@subsystem = N'ActiveScripting'</span><span>) and&nbsp;</span><span>serv_update.vbs</span><span>.</span><br><br>This issue affects OZOLS: before 1.1.1233."
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://offseq.com/en/research/ozols-cve-2026-22306",
                    "tags": [
                        "third-party-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "HIGH",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "HIGH",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 10,
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                    }
                },
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "CHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 10,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
                    }
                }
            ],
            "workarounds": [
                {
                    "lang": "en",
                    "value": "*  disable\n     or delete the <db>_update SQL\n     Server Agent job and remove serv_update.vbs;\n  *  block\n     outbound access from database servers and workstations to its2.lv / www2.its2.lv, and\n     restrict arbitrary outbound HTTP from those hosts;\n  *  disable xp_cmdshell on\n     affected SQL Server instances;\n  *  run the\n     SQL Server service under a least-privilege account;\n  *  inspect\n     the sprg table\n     for unexpected version increments or archive contents.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<ul><li><span>disable\n     or delete the&nbsp;</span><span>&lt;db&gt;_update</span><span>&nbsp;SQL\n     Server Agent job and remove&nbsp;</span><span>serv_update.vbs</span><span>;</span></li><li><span>block\n     outbound access from database servers and workstations to&nbsp;</span><span>its2.lv</span><span>&nbsp;/&nbsp;</span><span>www2.its2.lv</span><span>, and\n     restrict arbitrary outbound HTTP from those hosts;</span></li><li><span>disable&nbsp;</span><span>xp_cmdshell</span><span>&nbsp;on\n     affected SQL Server instances;</span></li><li><span>run the\n     SQL Server service under a least-privilege account;</span></li><li><span>inspect\n     the&nbsp;</span><span>sprg</span><span>&nbsp;table\n     for unexpected version increments or archive contents.</span></li></ul>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Nils Putniņš, OffSeq (SIA SEQ)",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "CERT.LV",
                    "type": "coordinator"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "references": [
                    {
                        "url": "https://offseq.com/en/research/ozols-cve-2026-22306/#s-04",
                        "tags": [
                            "exploit"
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-26T19:29:24.039857Z",
                                "id": "CVE-2026-22306",
                                "options": [
                                    {
                                        "Exploitation": "poc"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-26T19:29:42.941Z"
                }
            }
        ]
    }
}