A critical, easily exploitable flaw in Oracle Retail Integration Bus lets an unauthenticated attacker fully take over the product over the network, earning a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-46983 is a critical vulnerability in the Oracle Retail Integration Bus, part of Oracle Retail Applications, residing in the RIB Kernel component. Oracle rates it CVSS 3.1 base score 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw is described as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in complete takeover of Oracle Retail Integration Bus.
Why It Matters
The vulnerability requires no authentication, no user interaction, and low attack complexity; an attacker only needs network access over HTTP. Its impact is total: high confidentiality, integrity, and availability impacts, meaning a successful exploit can read, alter, and disrupt the affected system. Because Retail Integration Bus brokers data flows between retail applications, a takeover could cascade across connected systems.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Retail Integration Bus (component: RIB Kernel)
- Affected version: 16.0.3
Per the supplied record, version 16.0.3 is the supported version identified as affected.
Patch Status
Oracle addresses this issue in its Critical Patch Update of July 2026. Organizations running the affected version should consult the Oracle July 2026 Critical Patch Update advisory and apply the corresponding fixes.
This CVE is not present in the supplied CISA KEV data, so there is no confirmed record of active exploitation in the provided source material.