---
id: CVE-2026-46982
title: >-
  Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail
  Applications (component: RIB Kernal)
summary: >-
  Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail
  Applications (component: RIB Kernal).   The supported version that is affected
  is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker
  with…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: oracle
product: retail_integration_bus
affected:
  - retail_integration_bus = 14.1.3.2
published: '2026-07-21'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46982'
references:
  - url: 'https://www.oracle.com/security-alerts/cpujul2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00508
epssPercentile: 0.40851
ingestedAt: '2026-07-31T22:04:41.363Z'
---

## Overview

Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal).   The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

## Affected

- `retail_integration_bus = 14.1.3.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
