Oracle PeopleSoft CVE-2026-35273: ShinyHunters Bypasses WAF Rules in Renewed Attacks


Google Mandiant and Google Threat Intelligence Group reported renewed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft environments on September 25, 2026. The campaign uses URL-encoded variants of the vulnerable PSEMHUB path to reach systems whose perimeter controls block only the literal /PSEMHUB/ string.

Oracle rates CVE-2026-35273 at CVSS 3.1 9.8. The flaw affects supported PeopleSoft Enterprise PeopleTools 8.61 and 8.62, is remotely exploitable without authentication, and can result in remote code execution. Oracle originally released its Security Alert on June 10, 2026.

Mandiant attributes the renewed activity to UNC6240 (ShinyHunters) and reports web-shell deployment on dozens of systems globally across higher education, technology, IT services, healthcare, agriculture, transportation and government. Organizations that relied on path-based WAF blocking instead of applying Oracle's remediation should reassess exposure immediately.

The September campaign changes the perimeter assumption

Mandiant's June response guidance included restricting external access to the Environment Management Hub endpoint when organizations could not immediately patch or disable the service. In the renewed campaign, UNC6240 adapted to literal path filters by URL-encoding characters in the request path.

The documented example replaces /PSEMHUB/ with /%50SEMHUB/, where %50 represents the letter P. Mandiant explains that some WAFs and reverse proxies evaluate the literal path before URL decoding, while the PeopleSoft application stack decodes the request and routes it to the PSEMHUB application.

This makes normalization behavior operationally important. Defenders should account for percent-encoded, mixed-case and other non-normalized variants when reviewing perimeter controls and logs.

Affected versions and severity

Item Verified detail
CVE CVE-2026-35273
Product Oracle PeopleSoft Enterprise PeopleTools
Supported affected versions 8.61, 8.62
Component Updates Environment Management
Network authentication None required
CVSS v3.1 9.8
Potential impact Remote code execution
Oracle alert June 10, 2026
Renewed exploitation report September 25, 2026

Oracle says PeopleSoft Enterprise Applications customers may also be affected because of their PeopleTools dependency. Its advisory directs customers to the PeopleSoft patch-availability documentation for the applicable mitigation and installation instructions.

Immediate remediation priorities

Mandiant's current guidance puts the Oracle Security Alert remediation first. Operators should apply the Oracle fix for CVE-2026-35273 and keep PeopleTools on a supported version.

Where the Environment Management Hub is unnecessary, Mandiant also recommends disabling EMHub in multi-server configurations or removing the PSEMHUB application in single-server configurations according to Oracle's guidance. Administrative and system-to-system components should be restricted from unnecessary internet exposure.

A perimeter rule remains useful as defense in depth when it evaluates a normalized path. The September activity shows that a literal string rule alone leaves an avoidable parsing gap on an otherwise vulnerable server.

Hunt for activity that predates remediation

Patching closes the vulnerability but cannot establish whether an exposed server was previously accessed. Mandiant recommends retrospective review of both web and host telemetry.

Useful defensive checks include:

  • search PIA WebLogic access logs for /PSEMHUB/ and percent-encoded variants, especially external requests to the hub endpoint;
  • review requests to unexpected .jsp and .jspx files beneath PSEMHUB or PORTAL;
  • inspect the deployed PSEMHUB.war directory for files absent from the shipped product;
  • investigate shell processes such as cmd.exe, /bin/sh or bash spawned by the WebLogic Java process;
  • review outbound connections from PeopleSoft hosts against Mandiant's current network indicators;
  • inspect all WebLogic nodes behind a load balancer, because Mandiant observed repeated requests consistent with attempts to reach multiple backend nodes.

Mandiant specifically identifies filenames including x.jsp, u.jsp, tunnel.jsp, tunnel.jspx and Ple64.exe in observed intrusions. These are defensive hunt indicators; absence of those filenames does not exclude fileless command execution, which Mandiant also observed.

Credential and downstream response

Compromise of a PeopleSoft application tier can expose credentials and configuration reachable by the service account. Mandiant recommends rotating credentials readable by that account, including relevant database connection strings, Integration Broker credentials and reachable cloud credentials.

Organizations that identify compromise should also preserve forensic evidence before cleanup, review lateral movement from the affected host and validate the integrity of adjacent systems. Mandiant reports that some observed commands ran with root or NT Authority\\SYSTEM privileges, increasing the potential impact of a successful intrusion.

Why normalization matters beyond PeopleSoft

The defensive lesson is broader than this CVE: security controls and backend applications can interpret the same URL differently. Path filtering should operate on a canonicalized representation consistent with the application routing layer, and patching should remain the primary control for a remotely exploitable application vulnerability.

For PeopleSoft operators, the current decision is straightforward: systems running affected PeopleTools versions should receive Oracle's remediation, unnecessary EMHub exposure should be removed, and previously exposed servers should be reviewed for the activity documented by Mandiant.

Sources