DEV Community

Cover image for PeopleSoft CVE-2026-35273: one encoded letter beats WAFs
techaiwire
techaiwire

Posted on Originally published at techaiwire.com

PeopleSoft CVE-2026-35273: one encoded letter beats WAFs

The hacking group ShinyHunters is breaking into Oracle PeopleSoft servers again, using a flaw Oracle patched in June. This time the attackers slip past web application firewalls by changing a single letter. They write the "P" in /PSEMHUB/ as %50, its URL-encoded form. Firewall rules that block the literal path miss it, while the server decodes the request and runs the attack anyway.

Google's threat intelligence unit Mandiant described the new wave in a report published September 25, 2026. It says the attackers planted web shells on "dozens of systems globally." A web shell is a small script that gives an outsider a command line on the server.

The flaw behind it

The bug is CVE-2026-35273. It sits in PeopleSoft's Environment Management Hub, or PSEMHUB, a component that manages PeopleSoft installations. The Hacker News reports a CVSS score of 9.8 out of 10. CVSS is the standard scale security teams use to rank how dangerous a flaw is.

Mandiant calls it a Java deserialization flaw. The server takes a packaged Java object from a request and rebuilds it without checking it first. A crafted object can make the server run the attacker's code. No login is needed.

Mandiant tracks the group as UNC6240. It says the group first used the bug as a zero-day, meaning before any fix existed, between May 27 and June 9, 2026. Most victims then were universities. Oracle shipped an emergency Security Alert on June 10.

SecurityWeek reports that the June wave hit more than 100 PeopleSoft customers in education. It names the University of Nottingham, the insurance regulator NAIC and Nissan among the victims.

How one letter gets past the firewall

After June, many organizations added firewall rules that block any request to /PSEMHUB/. That stopped the old exploit. It did not fix the bug.

Mandiant explains the gap: "Many WAF and reverse proxy rules match the literal path before URL decoding." The PeopleSoft server, by contrast, decodes the path first. So /%50SEMHUB/ looks harmless to the firewall and identical to /PSEMHUB/ for the server.

Once inside, the group deployed these tools, according to Mandiant:

Tool What it does
x.jsp Runs commands sent in a POST request
u.jsp, u2.jsp Uploads files in 150 KB pieces
tunnel.jsp, tunnel.jspx Neo-reGeorg tunnel into the internal network
Ple64.exe Tampered Light Alloy media-player installer carrying the SIDEEYE backdoor
MeshAgent Remote-management agent kept for Linux persistence

The new wave reaches well beyond universities. Mandiant lists technology, IT services, healthcare, agriculture, transportation and government as well as higher education.

Why ShinyHunters matters here

ShinyHunters runs data-theft extortion. It steals data, then threatens to publish it unless the victim pays, SecurityWeek says. Google advises organizations to "prepare for extortion communications" and watch for stolen data appearing online, SecurityWeek notes.

What this means for developers

Install Oracle's patch for CVE-2026-35273. Mandiant says to apply the fix rather than rely on firewall filtering, and this campaign shows why. A blocklist rule matched on a literal string is one encoding trick away from failing.

If you do not use the Environment Management Hub, disable it or remove PSEMHUB entirely, as Mandiant advises. A component that is not deployed cannot be exploited.

Search your WebLogic logs for both /PSEMHUB/ and encoded forms such as /%50SEMHUB/, especially POST requests to the hub. Mandiant also says to check the PSEMHUB.war folder for files you did not put there. Look for unexpected MeshCentral agents too.

If you find signs of entry, rotate database and cloud credentials. An attacker with a shell on PeopleSoft may have read the connection details it uses.

The wider lesson applies to any web application behind a firewall. Rules that match paths should normalize the request first, decoding it the way the server will. Otherwise the firewall and the server are reading two different requests.


This article was first published on Tech AI Wire.

Also available in

Deutsch · 日本語 · Français · Español · Português

Sources

Top comments (0)