Skip to content

PeopleSoft CVE-2026-35273: one encoded letter beats WAFs

ShinyHunters is mass-exploiting Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) again, dodging WAF rules by writing one letter of the path as %50.

By Tech AI Wire Team

3 min read

XLinkedIn
A black rack-mount server with a red Oracle logo on its front panel, installed in a data-center rack lit by blue status lights.

By the numbers

CVSS severity of CVE-2026-35273
9.8 / 10
PeopleSoft customers hit in the June zero-day wave
100+
sectors targeted in the new wave
7

The hacking group ShinyHunters is breaking into Oracle PeopleSoft servers again, using a flaw Oracle patched in June. This time the attackers slip past web application firewalls by changing a single letter. They write the "P" in /PSEMHUB/ as %50, its URL-encoded form. Firewall rules that block the literal path miss it, while the server decodes the request and runs the attack anyway.

Google's threat intelligence unit Mandiant described the new wave in a report published September 25, 2026. It says the attackers planted web shells on "dozens of systems globally." A web shell is a small script that gives an outsider a command line on the server.

The flaw behind it

The bug is CVE-2026-35273. It sits in PeopleSoft's Environment Management Hub, or PSEMHUB, a component that manages PeopleSoft installations. The Hacker News reports a CVSS score of 9.8 out of 10. CVSS is the standard scale security teams use to rank how dangerous a flaw is.

Mandiant calls it a Java deserialization flaw. The server takes a packaged Java object from a request and rebuilds it without checking it first. A crafted object can make the server run the attacker's code. No login is needed.

Mandiant tracks the group as UNC6240. It says the group first used the bug as a zero-day, meaning before any fix existed, between May 27 and June 9, 2026. Most victims then were universities. Oracle shipped an emergency Security Alert on June 10.

SecurityWeek reports that the June wave hit more than 100 PeopleSoft customers in education. It names the University of Nottingham, the insurance regulator NAIC and Nissan among the victims.

How one letter gets past the firewall

After June, many organizations added firewall rules that block any request to /PSEMHUB/. That stopped the old exploit. It did not fix the bug.

Mandiant explains the gap: "Many WAF and reverse proxy rules match the literal path before URL decoding." The PeopleSoft server, by contrast, decodes the path first. So /%50SEMHUB/ looks harmless to the firewall and identical to /PSEMHUB/ for the server.

Once inside, the group deployed these tools, according to Mandiant:

ToolWhat it does
x.jspRuns commands sent in a POST request
u.jsp, u2.jspUploads files in 150 KB pieces
tunnel.jsp, tunnel.jspxNeo-reGeorg tunnel into the internal network
Ple64.exeTampered Light Alloy media-player installer carrying the SIDEEYE backdoor
MeshAgentRemote-management agent kept for Linux persistence

The new wave reaches well beyond universities. Mandiant lists technology, IT services, healthcare, agriculture, transportation and government as well as higher education.

Why ShinyHunters matters here

ShinyHunters runs data-theft extortion. It steals data, then threatens to publish it unless the victim pays, SecurityWeek says. Google advises organizations to "prepare for extortion communications" and watch for stolen data appearing online, SecurityWeek notes.

What this means for developers

Install Oracle's patch for CVE-2026-35273. Mandiant says to apply the fix rather than rely on firewall filtering, and this campaign shows why. A blocklist rule matched on a literal string is one encoding trick away from failing.

If you do not use the Environment Management Hub, disable it or remove PSEMHUB entirely, as Mandiant advises. A component that is not deployed cannot be exploited.

Search your WebLogic logs for both /PSEMHUB/ and encoded forms such as /%50SEMHUB/, especially POST requests to the hub. Mandiant also says to check the PSEMHUB.war folder for files you did not put there. Look for unexpected MeshCentral agents too.

If you find signs of entry, rotate database and cloud credentials. An attacker with a shell on PeopleSoft may have read the connection details it uses.

The wider lesson applies to any web application behind a firewall. Rules that match paths should normalize the request first, decoding it the way the server will. Otherwise the firewall and the server are reading two different requests.

Sources

  1. ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft - Google Cloud (Mandiant)
  2. Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign - SecurityWeek
  3. Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells - The Hacker News

Related articles

A black rack-mount network appliance with the NetScaler wordmark on its front bezel, on a plain gray backdrop.
Coding

Citrix NetScaler flaws: CISA sets a Sept. 30 deadline

CISA added two Citrix NetScaler flaws, both scoring 9.5 of 10 on the CVSS severity scale, to its exploited-vulnerability list on September 27, giving federal agencies until September 30 to patch.

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.