Oracle Hyperion Financial Management Multiple Critical Vulnerabilities
Release Date: 15th September 2026 (Added 16 September 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations, particularly government finance ministries, state-owned enterprises, and large businesses, that operate Oracle Hyperion Financial Management for financial consolidation, close, and reporting. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, and CVE-2026-87230 are eight critical vulnerabilities in the Security component of Oracle Hyperion Financial Management, version 11.2.26.0.000. Oracle Hyperion Financial Management is an enterprise financial consolidation and reporting platform used by government finance departments, state-owned enterprises, and large organizations globally - Oracle is a major enterprise software vendor already judged relevant to Vanuatu in prior advisories (Advisory 214, Oracle Reports Developer). All eight vulnerabilities were disclosed together as part of Oracle's September 2026 Critical Patch Update (CPU), which addressed 104 security patches across the wider Hyperion product family, 52 of which Oracle states may be remotely exploitable without authentication. All eight affect the identical Hyperion Financial Management version and Security component and are resolved by the same Critical Patch Update, so they are combined into this single advisory. Oracle disclosed the CPU on 15 September 2026.
What are the systems affected?
Affected systems are any Oracle Hyperion Financial Management instance running the version below.
Oracle Hyperion Financial Management, version 11.2.26.0.000 - (Affected)
Oracle Hyperion Financial Management, patched per Oracle's September 2026 Critical Patch Update - (Not affected, patched)
Any instance reachable over HTTP or Oracle Net from an untrusted network faces critical, confirmed risk: most of the eight flaws require no authentication at all, and one reaches CVSS 10.0.
What does this mean?
No user interaction is required for any of the eight flaws. A smaller number instead require an attacker who already holds high-privileged access.
Step 1 - Reach the Hyperion Financial Management Security Component
An unauthenticated remote attacker sends specially crafted requests to a reachable Oracle Hyperion Financial Management instance - over HTTP, Oracle Net (SQL*Net), or, for one flaw, from an adjacent network segment - targeting the Security component to bypass authentication and access controls. A smaller number of the eight flaws instead require an attacker who already holds high-privileged access.
Step 2 - Compromise or Fully Take Over the Financial Management System
Successful exploitation of the most severe flaws can result in complete takeover of Oracle Hyperion Financial Management, including unauthorized creation, deletion, or modification of critical financial data, and in several cases denial of service against the platform.
Successful exploitation may allow an attacker to gain unauthorized access to, or fully compromise, an Oracle Hyperion Financial Management instance, in most cases without any authentication, and to create, delete, or modify an organization's critical financial consolidation and reporting data without authorization, and in several cases cause denial of service against the platform itself.
Mitigation process?
CERTVU recommends the following:
-
Apply the Vendor Patch as an Emergency Change
Apply Oracle's September 2026 Critical Patch Update to every Oracle Hyperion Financial Management deployment without delay, given that six of the eight flaws require no authentication at all and one reaches CVSS 10.0. -
Restrict Network Access to Hyperion Financial Management
Limit access to Hyperion Financial Management's HTTP and Oracle Net (SQL*Net) interfaces to trusted internal networks, and avoid exposing them directly to the internet. -
Review Privileged Accounts on the Platform
Review accounts holding high-privileged access on the platform, and ensure their credentials have not been reused or compromised elsewhere. -
Review Financial-Data Audit Logs for Unauthorized Changes
Check financial-data audit logs for unauthorized creation, deletion, or modification of consolidation and reporting data.
Report any suspected compromise involving Oracle Hyperion Financial Management to CERTVU at
Reference
- https://www.oracle.com/security-alerts/cspusep2026.html
- https://www.cve.org/CVERecord?id=CVE-2026-87230
- https://www.cve.org/CVERecord?id=CVE-2026-87184
- https://www.cve.org/CVERecord?id=CVE-2026-87188
- Download advisory (English): Oracle Hyperion Financial Management Multiple Critical Vulnerabilities