PeopleSoft RCE CVE-2026-35273: ShinyHunters URL-Encode a Byte to Slip Past WAF Rules
🛡️ Security •

PeopleSoft RCE CVE-2026-35273: ShinyHunters URL-Encode a Byte to Slip Past WAF Rules

ShinyHunters restarted mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273 by percent-encoding one byte of the URL to slip past WAF rules that blocked the vulnerable path.

peoplesoftcve-2026-35273waf bypassshinyhuntersremote code execution

The extortion crew tracked as ShinyHunters has restarted mass exploitation of a critical Oracle PeopleSoft flaw, and the trick that reopened the door is almost insultingly small: they encode a single letter of the target URL so string-matching web application firewallFirewall🌐Security system that monitors and controls network traffic based on predetermined rules. rules stop recognizing the attack. The Google Threat Intelligence Group and Mandiant detailed the renewed campaign on 25 September 2026, and it is a clean case study in why a virtual patch bought you time, not safety.

What Happened

CVE-2026-35273 is an unauthenticated remote code execution vulnerabilityVulnerability🛡️A weakness in software, hardware, or processes that can be exploited by attackers to gain unauthorized access or cause harm. in Oracle PeopleSoft Enterprise PeopleTools, specifically the Updates Environment Management component that most administrators know as the Environment Management Hub, or EMHub. It carries a CVSS 3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and NVD and CISA classify it as CWE-306, missing authentication for a critical function. Reachable over HTTP without credentials, a successful request results in full takeover of the PeopleTools server.

Oracle released an out-of-band Security Alert for the flaw on 10 June 2026, crediting researchers from the Trend Zero Day Initiative and Trend Research. NVD published its record the next day. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 12 June 2026 with a three-day remediation deadline of 15 June, and flagged it for known ransomware campaign use. Only PeopleTools 8.61 and 8.62 are listed as affected, though Oracle notes that unsupported earlier releases are likely vulnerable and simply untested.

That was the first wave. Mandiant attributes the original zero-dayZero-Day🛡️A security vulnerability that is exploited or publicly disclosed before the software vendor can release a patch, giving developers 'zero days' to fix it. exploitation to UNC6240, the cluster publicly known as ShinyHunters, running from 27 May through 9 June 2026, roughly two weeks ahead of the advisory. Higher education took the brunt of it. In June, defenders were told to patch and, where they could not, to block external access to `/PSEMHUB/*` at the perimeter. Many organizations did exactly that with a WAF rule and moved on.

The One-Byte Bypass

The September campaign shows why that shortcut failed. The vulnerable endpoint is reached at the path `/PSEMHUB/`. The perimeter rules organizations deployed matched that literal string. So the attackers changed the request to `/%50SEMHUB/`, where `%50` is the percent-encoded form of the capital letter P.

The mechanism is a classic parser-normalization mismatch. Many WAF and reverse-proxy rules inspect the raw request path before it is URL-decoded, so `/%50SEMHUB/` does not match the block on `/PSEMHUB/`. The PeopleSoft application server, running on WebLogic, decodes the request afterward and happily routes it to the same vulnerable servlet. The block never fires, and the exploitExploit🛡️Code or technique that takes advantage of a vulnerability to cause unintended behavior, such as gaining unauthorized access. lands. Mandiant's guidance is blunt: defenders should assume any percent-encoded, mixed-case, or otherwise non-normalized variant of the path may be used, and should enforce blocking on the normalized path rather than a literal string. Our companion piece on why URL encoding lets attackers slip past string-matching WAF rules walks through the class of evasion in detail.

Before committing, the operators probe quietly. Mandiant observed 5 to 15 POST requests to `/%50SEMHUB/hub` carrying serialized Java objects; an unpatched server discloses its host operating system without writing files or disrupting service, letting the attacker confirm exploitability without tripping alarms. Learning to spot that pattern is the subject of our guide on how to hunt your web server logs for path-normalization evasion.

Who Is Affected

Mandiant reports web shells deployed on dozens of systems worldwide, and the target list has broadened well past the education sector that defined the first wave. Victims now span higher education, technology, IT services, healthcare, agriculture, transportation, and government. Any internet-exposed PeopleSoft deployment on PeopleTools 8.61 or 8.62 that was mitigated with a path-based WAF rule instead of the patch should be treated as a live target, and quite possibly as already compromised.

Technical Analysis

Once inside, the crew drops a small arsenal of JSP web shells into the PSEMHUB.war application directory. One, `x.jsp`, executes hex-encoded commands passed in a POST parameter and spawns `cmd.exe` or `/bin/sh` depending on the host OS. Another, `u.jsp` and its variant `u2.jsp`, reassembles base64-encoded file chunks to stage larger payloads. Two more, `tunnel.jsp` and `tunnel.jspx`, are the open-source Neo-reGeorg toolkit, used to proxy SOCKS traffic through the web server for internal discovery and lateral movementLateral Movement🛡️Techniques attackers use to move through a network after initial compromise, seeking additional systems to control and data to steal..

On Windows hosts, the operators deploy a multi-stage backdoor Mandiant calls SIDEEYE, delivered as `Ple64.exe`, a trojanized installer masquerading as the Light Alloy media player and signed with an Extended Validation certificate that has since been flagged for revocation. Its final C++ stage steals browser and application credentials and offers an interactive reverse shellReverse Shell🛡️A remote-access technique where a compromised host initiates an outbound connection back to the attacker and hands over a command shell. Because the connection originates inside the network, it often slips past firewalls that block inbound traffic.. On Linux, they install MeshAgent, a legitimate remote-management tool, under the PeopleSoft service accountService Account🛡️A non-human operating system or application account under which a service runs. Its permissions define the blast radius of any exploit against that service, since attacker code executes with the service account's access to files, secrets, and the network. and point it at attacker infrastructure. About a quarter of the observed commands ran as root or SYSTEM; the rest ran as the PeopleSoft or WebLogic service account, which is still more than enough to read database connection strings and integration credentials from configuration files.

UNC6240 has a well-worn playbook of data-theft extortion: exfiltrate, then threaten to publish on a leak site unless paid. Affected organizations should assume that data theft is the objective and prepare accordingly. Because the service account's stored secrets are within reach, a compromise here is not contained by pulling the box offline; it extends to every credential that account could read, a point we made earlier in our guide on how to rotate every secret after a server compromise.

Immediate Actions

Patch. Apply Oracle's Security Alert fix for CVE-2026-35273; a WAF rule is explicitly not a substitute. Where patching lags, disable the EMHub service or remove the PSEMHUB application entirely, and block the endpoint on the normalized, decoded path rather than a literal string.

Then hunt. Search WebLogic access logs for requests to `/PSEMHUB/` and any encoded variant such as `/%50SEMHUB/`, for POSTs to `/hub`, and for requests to `.jsp` files from external addresses. Inspect the PSEMHUB.war directory for `x.jsp`, `u.jsp`, `tunnel.jsp`, `tunnel.jspx`, and `Ple64.exe`. Alert on any shell process spawned by the WebLogic Java process. Known network indicators include the addresses 5.199.162.157, 104.219.234.138, and 162.219.30.165, and the domain winmanage-me.network. If you find any of it, rotate the credentials that the PeopleSoft service account can read before you do anything else.

Long-Term Outlook

The uncomfortable lesson is not about PeopleSoft. It is that compensating controls decay against a motivated adversary, and a WAF signature written around a literal path is one creative encoding away from irrelevant. Treat virtual patches as a countdown timer, not a fix, a discipline we expand on in why a WAF rule is a stopgap, not a substitute for patching. The organizations breached in September had months to apply the real patch after the June alert. The attackers only needed one byte.

Sources

  • Google Threat Intelligence Group / Mandiant, "ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft" (25 September 2026): https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
  • BleepingComputer, "ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks" (26 September 2026): https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
  • Oracle Security Alert Advisory - CVE-2026-35273 (10 June 2026): https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
  • NVD entry for CVE-2026-35273: https://nvd.nist.gov/vuln/detail/CVE-2026-35273
  • CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog