Description
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Retail Integration Bus 14.1.3.2 (component RIB Kernel) is an Improper Authorization flaw (CWE‑284). An unauthenticated attacker can send crafted HTTP requests to the bus, resulting in full system compromise. The flaw permits remote code execution and takeover, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle Retail Integration Bus version 14.1.3.2 from Oracle Corporation’s Retail Applications suite is the only product identified as vulnerable. No other versions or products are listed in the CVE data.

Risk and Exploitability

The CVSS v3.1 Base Score of 9.8 reflects critical severity across all dimensions, and the vector indicates network access, low complexity, no privileged user, and no user interaction. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present, and the vulnerability has not yet been listed in CISA KEV. Attackers can exploit the weakness from any location with HTTP access to the RIB bus, sending forged requests to bypass authentication and execute arbitrary commands.

Generated by OpenCVE AI on August 4, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Retail Integration Bus patch released in the July 2026 CPU alert, after verifying the update covers version 14.1.3.2.
  • Block or tightly restrict HTTP access to the RIB bus to trusted IP addresses or networks, using firewall rules or proxy restrictions.
  • Enable detailed logging for authentication attempts and anomalous traffic, and monitor logs for signs of unauthorized access or exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables Total Compromise of Oracle Retail Integration Bus

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Retail Integration Bus via HTTP

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Retail Integration Bus via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle retail Integration Bus
CPEs cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle retail Integration Bus
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Retail Integration Bus
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:17:03.483Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46982

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:42.013Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:03.240

Modified: 2026-07-31T15:07:37.327

Link: CVE-2026-46982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses