Oracle Hyperion Financial Management Multiple Critical Vulnerabilities

Release Date: 15th September 2026 (Added 16 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, particularly government finance ministries, state-owned enterprises, and large businesses, that operate Oracle Hyperion Financial Management for financial consolidation, close, and reporting. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, and CVE-2026-87230 are eight critical vulnerabilities in the Security component of Oracle Hyperion Financial Management, version 11.2.26.0.000. Oracle Hyperion Financial Management is an enterprise financial consolidation and reporting platform used by government finance departments, state-owned enterprises, and large organizations globally - Oracle is a major enterprise software vendor already judged relevant to Vanuatu in prior advisories (Advisory 214, Oracle Reports Developer). All eight vulnerabilities were disclosed together as part of Oracle's September 2026 Critical Patch Update (CPU), which addressed 104 security patches across the wider Hyperion product family, 52 of which Oracle states may be remotely exploitable without authentication. All eight affect the identical Hyperion Financial Management version and Security component and are resolved by the same Critical Patch Update, so they are combined into this single advisory. Oracle disclosed the CPU on 15 September 2026.

Reference

  1. https://www.oracle.com/security-alerts/cspusep2026.html
  2. https://www.cve.org/CVERecord?id=CVE-2026-87230
  3. https://www.cve.org/CVERecord?id=CVE-2026-87184
  4. https://www.cve.org/CVERecord?id=CVE-2026-87188