Oracle's rolling Premier Support promise for Hyperion 11.2 hides a patch-eligibility trap that can strand you without security fixes even while you pay. This guide quantifies the security gap and lays out the three real paths (third-party support, stay put, or EPM Cloud) with the numbers each one demands.
Life After Certification
Session 11 of the Oracle ULA Series. Ten years of support on a certified position costs roughly two and a half times the licence value itself. What you now own, what the count constrains, the governance that has to arrive with the certificate, and the options certification hands back.
Oracle's rolling Premier Support promise for Hyperion 11.2 hides a patch-eligibility trap that can strand you without security fixes even while you pay. This guide quantifies the security gap and lays out the three real paths (third-party support, stay put, or EPM Cloud) with the numbers each one demands.
Oracle's support lifecycle has three tiers, and the difference between them is worth millions in security exposure. Premier Support gives you new updates, fixes, and security patches. Extended Support (rarely offered for Hyperion) buys a defined runway at a premium. Sustaining Support, the tier that older Hyperion versions have already fallen into, gives you almost nothing new. Per Bart Partners (June 2025), "Sustaining Support gives only access to the existing knowledge base and previously released patches. You will no longer receive new updates." There is no defined end date for Sustaining Support, which sounds generous until you realize it is because Oracle has stopped investing in the code entirely.
Clients on Oracle Hyperion 11.1.2.4 entered Sustaining Support at the beginning of January 2022, per IT Convergence (June 2025), with "extremely limited support options and no access to new features, improvements, fixes, or security patches." That is the practical meaning of the tier: you keep the right to open a ticket and search old notes, and you lose the right to have any new defect or vulnerability corrected. For a system that consolidates your financials, that is not a support tier, it is a countdown clock.
For a full map of where each Hyperion version sits and how the metrics work, start with our Oracle Hyperion EPM on-premise licensing guide. This subpage focuses narrowly on the support-lifecycle decision the 2026 timeline forces.
Oracle and its partner ecosystem now cite Premier Support for Hyperion 11.2 "through at least 2036" (US-Analytics, 2025). Read the fine print before you plan a decade around it. Per Bart Partners (June 2025): "For Hyperion 11.2, Oracle guarantees Premier Support until at least 2036. This guarantee is revised annually." Earlier Oracle documents cited at least 2030, then 2032, then 2033, then 2034. The date has been rolled forward year by year.
The honest reading, from 25 years watching Oracle manage lifecycle dates, is that the 2036 figure is a marketing anchor designed to keep customers off third-party support and out of a rushed cloud decision. It is credible enough to be real, and soft enough that Oracle can adjust it. Do not build a capital plan on the far end of that window. Build it on the near-term patch mechanics below, which are governed by policy documents Oracle can and does change.
The 2036 date has been 2030, 2032, 2033, and 2034 in prior documents. It is an annual promise dressed as a decade.
This is the single most misunderstood fact about Hyperion 11.2, and it is where most estates carry silent risk. Being on 11.2 is not enough to receive fixes. Per Bart Partners (June 2025): "Just being on 11.2 is not enough to ensure your defects will be fixed. Only certain release updates of 11.2 are eligible for bug fixes and patching. As of now, the release updates eligible for fixes are 11.2.18 or higher." The eligible floor moves upward over time. EPM 11.2.22 was available as of mid-2025 (Oracle Proactive Support, July 2025).
The mechanics are governed by two notes: the Oracle EPM 11.2 Software Error Correction Policy (Doc ID 2749950.1) and Grace Periods for Error Correction (Doc ID 2627593.1). Once a release update passes its grace-period end date, "no additional fixes will be developed" for it. Translation: you can be a fully paid Premier Support customer, sitting on an outdated 11.2.x build, and be functionally on sustaining support for your specific release because Oracle has stopped correcting errors on it. Paying the bill does not protect you. Staying current does.
Every organization running Hyperion should confirm its exact release update against the current eligibility floor this quarter, not next year. If you are below 11.2.18, you are already outside error correction on that build regardless of what your renewal invoice says. That is a compliance and security finding, and it is one an auditor or a security review will surface at the worst possible moment. Our Hyperion audit defense guide covers how patch posture intersects with an option-usage review.
The abstract risk of a patching gap becomes concrete when you count the actual vulnerabilities. Oracle's Critical Patch Update stream shows a steady quarterly flow of Hyperion CVEs, most of them serious. The January 2026 CPU contained 12 new security patches for Oracle Hyperion, and 10 of those vulnerabilities may be remotely exploitable without authentication. The April 2026 CPU contained 6 new Hyperion patches, 4 of them remotely exploitable without authentication.
Source: Oracle Critical Patch Updates, January and April 2026.
| CPU cycle | New Hyperion patches | Remotely exploitable w/o auth |
|---|---|---|
| January 2026 | 12 | 10 |
| April 2026 | 6 | 4 |
Two quarters alone produced 14 remotely exploitable, unauthenticated vulnerabilities in Hyperion. On a run rate like that, an estate that falls out of patch eligibility (whether by dropping to sustaining support or by sitting on an outdated 11.2 build) accumulates roughly 40 to 60 unpatched Hyperion CVEs per year, most of them network-exploitable. For a system holding consolidated financial data, that is not a theoretical exposure, it is a live audit and cyber-insurance problem. Note that platform modernization is tied to staying current: version 11.2 brought Fusion Middleware 12g, Java 8, and Oracle HTTP Server 12c, enabling TLS 1.2, and 11.2.15 introduced Linux 8 certification. Falling behind on release updates also freezes your platform stack.
Oracle's preferred exit is EPM Cloud, and the sales motion around Hyperion end-of-life is engineered to push you there. Understand the pricing before you accept the premise. List pricing runs two tiers: Standard at $250 per user per month (Planning, Account Reconciliation, Financial Consolidation and Close) and Enterprise at $500 per user per month (adding Profitability and Cost Management, Tax Reporting, and Enterprise Data Management), per Redress Compliance (April 2026).
The metric is where Hyperion migrants get hurt. EPM Cloud operates exclusively on the Hosted Named User metric: every unique individual who accesses the platform needs a dedicated subscription. There is no concurrent user option and no shared login. Per Redress Compliance (April 2026), this is "a critical distinction for enterprises migrating from on-premises Hyperion, where many organizations relied on a smaller pool of concurrent licenses to serve a larger user population." A 200-concurrent-user Hyperion estate can map to 600 or more named users in the cloud. Model your named-user headcount before you take a per-user quote seriously.
Legacy PBCS (around $120 per user per month) and EPBCS (around $250) have folded into these tiers (The Negotiation Experts, June 2026), so most existing Hyperion planning customers land on Standard or Enterprise depending on module breadth. The full migration cost picture, including data conversion and parallel-run periods, sits in our Hyperion to EPM Cloud migration cost analysis.
A 200-concurrent Hyperion estate can become 600-plus named cloud users. Count heads before you accept a per-seat quote.
If your Hyperion estate is stable and you can accept life without new Oracle features, third-party support is the highest-leverage financial move. Providers like Rimini Street market roughly 50% savings against Oracle's standard 22% annual support rate, and up to 90% on total cost of ownership (Rimini Street, April 2026). Rimini has supported Hyperion since 2012, covering HFM, Hyperion Planning, Essbase, and Financial Data Quality Management (Redress Compliance, April 2026).
The cost math driving this decision is Oracle's own escalator. Oracle charges annual support at 22% of the original license fee, with fees increasing 8% per year (Redress Compliance, April 2026). That default uplift is not aspirational: across 60 to 80 Oracle support renewals benchmarked in 2024 and 2025, the letter arrived at the default 8 percent uplift more than nine times out of ten (Redress Compliance, February 2026). Left unchallenged, your Hyperion support line doubles roughly every nine years while the product stays frozen.
Two traps must drive the timing of any exit. First, the reinstatement penalty: if you leave and later want back onto Oracle support, Oracle charges roughly 150% of the accumulated missed support fees plus back support for the gap years. On a $2M annual bill, re-entry after two years costs more than $6M upfront before ongoing fees resume (Redress Compliance, February 2026). Second, the all-or-nothing rule: canceling support requires canceling all licenses of a given product at once. Keeping Oracle support on a subset while moving the rest triggers contract violations and repricing on the retained licenses (Redress Compliance, February 2026).
The screening logic is straightforward. Third-party support fits when your Hyperion version is stable, you have no near-term cloud commitment, your audit posture is clean, and you are current enough on patches to accept freezing there. Our broader frameworks (the third-party support decision framework and the Oracle third-party support 2026 analysis) walk the four-question screen. For the Hyperion-specific version of this decision, including which modules a provider will and will not cover, see Hyperion on third-party support.
Staying put is a legitimate path, but only if you execute it disciplined. "Staying" does not mean freezing on your current build. It means committing to a patch cadence that keeps you above Oracle's error-correction floor (currently 11.2.18 or higher, moving up over time) and applying quarterly CPUs. If you pay Premier Support and let your release update lapse below the eligible floor, you get the worst of both worlds: full price, sustaining-support reality.
The financial defense on this path is the renewal negotiation. The 8% uplift is a default, not a contractual inevitability on most agreements. Every Hyperion renewal is an opportunity to cap or eliminate the uplift, and skipping that fight is how estates end up paying 22% of a license fee that is now two or three times larger than the software's market value. Our note on the buyer-side route out of Oracle support quantifies the compounding cost you are agreeing to when you sign a default renewal.
One structural caution for the stay-put path: the licensing buried underneath Hyperion. Many Hyperion deployments carry embedded Oracle Database and WebLogic entitlements whose scope is poorly documented. Before you commit to another support cycle, confirm what you are actually paying for, because that stack is a favorite audit vector. Our Hyperion embedded database and WebLogic exposure guide covers it, and the metric question (Named User Plus versus Processor) is handled in our Named User Plus vs Processor guide.
The 2026 decision is not urgent because 11.2 is about to die. It is urgent because the patch-eligibility trap can put you on de facto sustaining support today, and because every year you accept a default renewal compounds your cost by 8%. Take three concrete actions this quarter.
Whichever path you choose, the mistake to avoid is drifting. Oracle's rolling 2036 promise is designed to keep you comfortable and passive. Passive is the most expensive posture available, because it means paying full support for a frozen product while your specific build quietly falls out of error correction. Pick a path deliberately, and price it before Oracle prices it for you.
Oracle currently cites Premier Support for Hyperion 11.2 through at least 2036, but that date is revised annually and has previously been stated as 2030, 2032, 2033, and 2034. Treat 2036 as a rolling promise, not a fixed guarantee. Your near-term risk is patch eligibility on your specific release update, not the far-end date.
No. Only certain 11.2 release updates are eligible for bug fixes and error correction (currently 11.2.18 or higher, and the floor moves upward). If your build is below the eligible level or past its grace-period end date, Oracle develops no new fixes for it even though you are paying full support. You must stay on a current release update to keep receiving corrections.
Oracle's quarterly Critical Patch Updates show a steady flow of Hyperion vulnerabilities: 12 new patches in January 2026 (10 remotely exploitable without authentication) and 6 in April 2026 (4 remotely exploitable). An estate that stops receiving patches accumulates roughly 40 to 60 unpatched Hyperion CVEs per year, most network-exploitable, which becomes a serious audit and cyber-insurance problem.
Oracle charges roughly 150% of the accumulated missed support fees plus back support for the gap years. On a $2M annual bill, re-entry after two years exceeds $6M upfront before ongoing fees resume. This penalty is the main reason third-party support should be treated as a one-way decision unless you are certain of your cloud path.
EPM Cloud lists at $250 per user per month (Standard) or $500 (Enterprise) and uses the Hosted Named User metric only, with no concurrent option. Because Hyperion estates often ran a small concurrent pool serving a larger population, your named-user count can multiply two or three times on migration, and subscriptions compound annually (a $1M/year deal is over $6M across six years with renewals).
No. Oracle's policy requires you to cancel all licenses of a given product at once when you leave support. Keeping Oracle support on a subset while moving others to third-party support triggers contract violations and repricing on the licenses you retain. Plan any exit as an all-or-nothing move per product.
When third party support is the right call for Oracle Database, Apps, and Middleware. Rimini Street, Spinnaker, the savings math, and the leverage even non sw
Gated with a work email on the download page. No sales follow up you did not ask for.
Get the White Paper →500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.