ShinyHunters Bypasses PeopleSoft WAF in Renewed Exploitation

ShinyHunters is bypassing PeopleSoft WAF rules with an encoded request path to resume mass exploitation of critical CVE-2026-35273.

Sep 29, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

ShinyHunters is exploiting Oracle PeopleSoft CVE-2026-35273 again by using a one-character URL-encoding technique to bypass web application firewall rules that some organizations deployed instead of patching.

Google’s Mandiant and Threat Intelligence Group, which track the group as UNC6240, say the renewed campaign has placed web shells on dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation, and government.

The affected systems remained vulnerable to CVE-2026-35273. Oracle’s patch addresses the vulnerability, but systems relying only on WAF rules can still be exposed to the bypass.

PeopleSoft WAF bypass uses one encoded character

Instead of requesting /PSEMHUB/, the path many organizations blocked at the firewall as an interim measure, ShinyHunters requests /%50SEMHUB/. The sequence %50 is the percent-encoded form of the letter "P," according to Mandiant's analysis.

Many WAFs and reverse proxies compare the literal request path against their rules before decoding it. A rule written to catch /PSEMHUB/ may not match /%50SEMHUB/.

WebLogic decodes the path before routing it, turning %50 back into "P" and sending the request to the vulnerable endpoint.

Mandiant warns that %50 is only one variant ShinyHunters has used. The group could switch to other percent-encoded characters, mixed casing, or alternate path representations.

Organizations should not rely on signature-based WAF rules as a substitute for Oracle’s security update.

CVE-2026-35273 gives attackers unauthenticated RCE

CVE-2026-35273 is a CVSS 9.8 unauthenticated remote-code-execution vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools 8.61 and 8.62.

Oracle's security alert says the flaw can be exploited remotely without authentication and may result in full compromise of PeopleSoft Enterprise PeopleTools. Oracle released the alert and patch on June 10.

Advertisement

One day later, Mandiant and GTIG published a report tying active exploitation to ShinyHunters and confirming that attacks had been running since May 27, roughly two weeks before Oracle's advisory. That made CVE-2026-35273 a PeopleSoft zero-day during the original campaign.

Trend Micro's technical analysis describes the underlying chain as SSRF-to-RCE. The PSIGW Integration Broker gateway can be abused to reach an internal management servlet, which eventually triggers Java XMLDecoder deserialization inside the WebLogic JVM.

The final stage can execute inside the WebLogic JVM on a web-tier restart without spawning a child process or requiring an outbound beacon. Detection rules focused only on Java spawning a shell or an obvious network exploit may therefore miss the activity.

Google notified more than 100 organizations whose systems correlated with potentially vulnerable endpoints during the original campaign. Sixty-eight percent were higher-education institutions, mostly in the US.

ShinyHunters moves from reconnaissance to web shells

Mandiant says the renewed attacks often begin with five to 15 POST requests to /%50SEMHUB/hub carrying serialized Java objects.

On vulnerable systems, those requests can return information about the host operating system without writing files or disrupting the service. This allows the attackers to confirm whether a target is vulnerable before continuing.

Once exploitation begins, Mandiant has observed direct command execution and JSP web shell deployment.

The group uses x.jsp for command execution and u.jsp and u2.jsp to upload larger files. It has also deployed the open-source Neo-reGeorg tunneling toolkit through tunnel.jsp and tunnel.jspx.

On compromised Windows servers, those shells have been used to deploy Ple64.exe, disguised as a signed Light Alloy media player installer. The executable installs a backdoor Google tracks as SIDEEYE, which supports credential theft, file and process management, interactive reverse shells, and reverse proxy functionality.

Advertisement

On Linux systems, ShinyHunters has used the legitimate MeshAgent remote-management tool to maintain access.

The original May-to-June campaign also involved customized MeshCentral agents disguised with filenames resembling legitimate Azure tooling, lateral-movement scripts, data staging, and exfiltration activity.

Those behaviors were documented in the original campaign and are not confirmed in every current intrusion.

Patching closes the vulnerability ShinyHunters is currently exploiting, but it does not remove access already established before remediation.

Mandiant recommends applying Oracle's security update for CVE-2026-35273 immediately.

Organizations that cannot patch immediately should disable the Environment Management Hub service in multi-server configurations or remove the PSEMHUB application in single-server configurations.

For detection, Mandiant recommends checking WebLogic access logs for:

  • POST /PSEMHUB/hub
  • Encoded variants such as POST /%50SEMHUB/hub
  • External requests to unexpected .jsp or .jspx files
  • Requests targeting /PSIGW/HttpListeningConnector

Organizations should also inspect the PSEMHUB application directory for files that are not part of the shipped product, including:

  • x.jsp
  • u.jsp
  • tunnel.jsp
  • tunnel.jspx
  • Ple64.exe

Trend Micro's analysis also recommends checking envmetadata/transactions/ and envmetadata/data/environment/ for unauthorized content associated with the exploit chain.

Given the documented use of web shells, SIDEEYE, MeshAgent, and tunneling utilities, defenders should review outbound network traffic, database activity, unexpected archive files, and credential use for signs that an attacker moved beyond the PeopleSoft server.

Mandiant also recommends rotating credentials readable by the PeopleSoft application service account, including database connection strings, Integration Broker credentials, and reachable cloud credentials.

If a web shell or backdoor is found, the affected host should be treated as compromised rather than simply patched and returned to service.

Advertisement

FBI breach claims remain unverified

The renewed PeopleSoft activity follows a separate claim from ShinyHunters involving FBIjobs.gov.

The group told BleepingComputer that it used the same WAF bypass against FBI Jobs and also claimed to have exploited a separate, unknown PSEMHUB vulnerability.

ShinyHunters claims it moved laterally into AWS GovCloud infrastructure and stole between 2TB and 3TB of data tied to current and former FBI employees, job applicants, and other internal systems.

BleepingComputer could not independently verify the alleged second vulnerability, the claimed lateral movement, or the amount of data reportedly stolen.

The FBI confirmed only that it was investigating unauthorized activity affecting FBIjobs.gov. It has not confirmed a broader breach, data theft, or access to AWS GovCloud.

Patching does not remove existing access

Mandiant says the renewed campaign has already deployed web shells on dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation, and government.

Oracle's patch closes CVE-2026-35273, but it does not remove web shells, backdoors, stolen credentials, or other access already established before remediation.

Organizations that relied on WAF rules instead of patching should investigate for compromise rather than only update the firewall rule.

They should patch the vulnerability, review logs and filesystem artifacts, inspect outbound traffic, rotate exposed credentials, and treat confirmed attacker artifacts as an incident.

Also read: Security teams responding to active exploitation should also review the latest SharePoint CVE-2026-65660 attacks and CISA's accompanying remediation requirements.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.