NEWS

ShinyHunters Bypass WAFs to Exploit Oracle PeopleSoft Flaw at Scale

Google warns ShinyHunters is mass-exploiting a patched PeopleSoft RCE flaw again, using URL-encoding to slip requests past WAFs.

Dylan H.

News Desk

September 27, 2026
4 min read
ShinyHunters Bypass WAFs to Exploit Oracle PeopleSoft Flaw at Scale

A Patched Vulnerability Comes Back Around

Google's Threat Intelligence Group (GTIG), working with Mandiant, is warning of a renewed mass exploitation campaign targeting Oracle PeopleSoft deployments — reusing a vulnerability Oracle already patched, by simply encoding requests in a way that slips past web application firewalls (WAFs) configured to block the original attack pattern. The activity is linked to ShinyHunters, the extortion-focused group Mandiant tracks internally as UNC6240.

The vulnerability at the center of the campaign is CVE-2026-35273, an unauthenticated remote code execution flaw (CVSS 9.8) in PeopleSoft's Environment Management Hub (PSEMHUB), affecting PeopleTools 8.61 and 8.62. It was first exploited as a zero-day between May 27 and June 9, 2026 against academic institutions, before Oracle shipped a patch on June 11, 2026. Google's September 2026 advisory documents its return — this time against a broader, global set of targets.


The Bypass: A One-Character Trick

The technique attackers are using to evade WAF rules is strikingly simple: URL-encoding the letter "P" in the vulnerable path. A request to /PSEMHUB/hub gets rewritten as /%50SEMHUB/hub. WAF rules that match the literal string PSEMHUB in a request path miss the encoded variant entirely — but the underlying PeopleSoft/WebLogic application stack decodes the URL before routing it, so the request still reaches the vulnerable handler exactly as intended.

Google warns that other encodings and mixed-case variants of the same trick could follow, meaning organizations relying solely on string-matching WAF rules for this vulnerability should not consider themselves protected even if such a rule is already in place.


Campaign at a Glance

AttributeDetail
VulnerabilityCVE-2026-35273 — unauthenticated RCE in PeopleSoft Environment Management Hub (PSEMHUB), CVSS 9.8
Affected versionsPeopleSoft Enterprise PeopleTools 8.61 and 8.62
Original zero-day windowMay 27 – June 9, 2026 (academic institutions)
Oracle patchJune 11, 2026
Renewed campaign identifiedSeptember 2026, by Google Threat Intelligence Group / Mandiant
Evasion techniqueURL-encoding "P" as %50 (e.g. /%50SEMHUB/hub) to bypass literal-string WAF rules
Attributed actorShinyHunters, tracked by Mandiant as UNC6240
Targeted sectorsHigher education, technology, IT services, healthcare, agriculture, transportation, government
Scale"Dozens" of newly compromised systems identified globally

Tooling Deployed Post-Compromise

Once inside, the campaign deploys a mix of custom and off-the-shelf tooling:

  • JSP web shells — files named x.jsp and u.jsp dropped for persistent command access.
  • SIDEEYE — a C++ backdoor supporting credential theft, file and process management, and reverse-shell functionality.
  • Ple64.exe — a trojanized installer used to establish footholds.
  • Neo-reGeorg — an open-source tunneling tool used to pivot through the compromised host.
  • MeshAgent — legitimate remote-monitoring-and-management (RMM) software repurposed for long-term persistence.

Who Is ShinyHunters

ShinyHunters, tracked by Mandiant as UNC6240, rebranded from the earlier GnosticPlayers identity around 2020 and has operated primarily as a data-theft extortion actor rather than a traditional ransomware crew — stealing data and threatening publication rather than encrypting systems. The group has been separately linked this year to a breach of the FBI's FBIJobs.gov recruiting portal, reportedly via a different PeopleSoft zero-day, underscoring a pattern of targeting the same enterprise software family across multiple campaigns.


Recommendations

For Oracle PeopleSoft Administrators

  • Confirm the June 11, 2026 patch for CVE-2026-35273 is applied — this is the only complete fix. WAF rules are not a substitute.
  • Disable or remove the Environment Management Hub (PSEMHUB) if it is not actively required.
  • Scan WebLogic access logs for requests to /PSEMHUB/ and percent-encoded variants such as /%50SEMHUB/, including mixed-case permutations.
  • Inspect PSEMHUB.war and related deployment directories for unauthorized JSP files, particularly x.jsp and u.jsp.

For Security and Incident Response Teams

  • Rotate credentials for any PeopleSoft-associated accounts on systems that were internet-facing and unpatched during either exploitation window.
  • Monitor database audit logs for bulk queries and unusual outbound traffic originating from PeopleSoft hosts.
  • Do not treat WAF coverage as verification of remediation — this campaign specifically demonstrates that literal-string WAF rules can be bypassed while the underlying flaw remains unpatched.

Sources