Oracle PeopleSoft Under Renewed Attack: Attackers Sidestep WAFs to Plant Web Shells
A financially motivated group with ties to the ShinyHunters collective is running a fresh wave of attacks against Oracle PeopleSoft deployments, using a simple URL-encoding trick to slip past web application firewalls that were supposed to block the exploit.
What happened
Security researchers tracking the activity, internally labeled UNC6240, report that the threat actor has updated an existing PeopleSoft exploit chain built around CVE-2026-35273, a critical (CVSS 9.8) flaw that allows unauthenticated remote code execution against the platform's Environment Management Hub (PSEMHUB) component.
The vulnerability was originally weaponized as a zero-day against academic institutions, where it was used for reconnaissance, credential theft, and lateral movement over SSH between PeopleSoft servers sharing default or reused credentials. Since then, over 100 organizations worldwide — most based in the US — have been notified that their exposed PeopleSoft endpoints matched the vulnerable signature.
What makes this new wave notable is the bypass technique itself: many WAF and reverse-proxy rules block requests to the literal string /PSEMHUB/hub, but they inspect the path before URL decoding happens. By encoding a single character — sending /%50SEMHUB/hub instead — the attacker's request slides past the filter untouched, and the PeopleSoft application server decodes it and routes it straight to the vulnerable servlet anyway.
From there, the group abuses Java deserialization in the PSEMHUB servlet to drop web shells, including one built for cross-platform command execution and another that handles chunked file uploads. Those web shells have been used to deliver a signed, trojanized installer that loads a backdoor in memory — giving the attacker credential theft, file management, and reverse-proxy capabilities, with roughly a quarter of observed commands executing with full system or root privileges. Persistence is maintained through a legitimate remote-management tool and an open-source tunneling utility, both repurposed to blend in with normal administrative traffic.
The targeting spans technology, education, healthcare, government, agriculture, and transportation organizations, with web shells confirmed on dozens of separate systems.
Why it matters
This isn't a new vulnerability — it's proof that patching alone doesn't close the door if compensating controls like WAF rules are written against the literal request string instead of the fully decoded path. Any organization that leaned on a firewall signature rather than the underlying patch is exposed the moment the attacker tweaks the encoding, which is exactly what happened here.
The group behind this activity has a well-documented pattern of data theft followed by extortion: steal first, then threaten to leak on a dedicated data-leak site if the victim doesn't pay. Given the sensitivity of what typically lives in PeopleSoft — HR, payroll, and in some sectors student records — a successful compromise carries real regulatory and reputational exposure well beyond the initial technical breach.
What to do
- Patch immediately against CVE-2026-35273 if you haven't already — this is the only fix that closes the underlying flaw regardless of how WAF rules are written.
- Reduce exposure: disable the Environment Management Hub service where it isn't needed in multi-server setups, or remove the PSEMHUB application entirely on single-server installs.
- Audit access logs for requests to
/PSEMHUB/and, critically, for percent-encoded variants of the same path — a WAF rule that only matches the plain string will miss this. - Hunt for web shells in the PSEMHUB working directory and any unexpected
.jspfiles nearby. - Rotate credentials accessible to the PeopleSoft application service account, and review database audit logs for unusual bulk exports touching HR, payroll, or records tables.
- Monitor outbound traffic from PeopleSoft hosts for connections to unfamiliar external addresses.
If your organization runs PeopleSoft and hasn't validated patch status against this CVE this week, treat it as a priority — this is active, ongoing exploitation, not a theoretical risk.
