Description
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Retail Integration Bus represents a CWE-284 Improper Access Control flaw. It allows an unauthenticated attacker with HTTP network access to fully compromise the system, exposing all data and control capabilities. This flaw results in loss of confidentiality, integrity, and availability, effectively giving the attacker full administrative control of the integration bus.

Affected Systems

Oracle Retail Integration Bus version 16.0.3 is affected. No other versions were listed by Oracle or in the available data.

Risk and Exploitability

The CVSS score of 9.8 emphasizes the severity of the flaw, and the EPSS score of less than 1% suggests exploitation probability is presently low, though it remains low‑complexity and requires no user interaction. Because the attack vector is network and the access requirement is none, an attacker can trigger the vulnerability by sending a crafted HTTP request to the target. The flaw is not listed in CISA’s KEV catalog, but the lack of authentication and network scope make it a high‑risk exposure for any customer running the vulnerable version.

Generated by OpenCVE AI on August 4, 2026 at 05:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or upgrade to a fixed version as detailed in Oracle’s CPU July 2026 security alert
  • Enforce strict access control on all interfaces, ensuring only authenticated and authorized users can interact with the Retail Integration Bus
  • Review and enforce network segmentation to restrict external HTTP access to the Retail Integration Bus
  • Enable logging and monitor for anomalous HTTP traffic that could indicate exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 05:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leads to Full System Compromise of Oracle Retail Integration Bus 16.0.3

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leads to Full System Compromise of Oracle Retail Integration Bus 16.0.3

Mon, 27 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Retail Integration Bus
Weaknesses CWE-693

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Retail Integration Bus
Weaknesses CWE-693

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle retail Integration Bus
CPEs cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle retail Integration Bus
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Retail Integration Bus
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:16:53.824Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46983

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:40.625Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:03.347

Modified: 2026-07-31T15:18:35.987

Link: CVE-2026-46983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses