ShinyHunters has renewed exploitation of critical Oracle PeopleSoft vulnerability CVE-2026-35273, using a small change in request encoding to bypass web application firewall rules that some organizations relied on for protection. Google Cloud researchers linked the activity to UNC6240, the group commonly known as ShinyHunters, and observed web shells on dozens of systems worldwide.
The flaw was previously exploited as a zero-day against universities. The newer campaign has expanded across technology, IT services, healthcare, agriculture, transportation and government organizations. Because PeopleSoft frequently holds human-resources, payroll, student and operational information, a successful breach can quickly become a data-theft and extortion event.
An encoded character defeats literal blocking
The bypass exploits a difference in how security layers interpret a URL. Attackers percent-encode one character in the vulnerable PSEMHUB route. Some WAFs and reverse proxies compare the request with a literal block rule before decoding it, so the altered text does not match. The PeopleSoft application server later decodes the path and sends it to the vulnerable service.
This is a classic normalization gap: two components see logically identical requests in different forms. It also explains why a virtual patch at the perimeter is less reliable than correcting the underlying software. A rule that stops the original exploit string may fail when an attacker changes representation without changing meaning.
The group typically issued several POST requests carrying a serialized Java object to test a target. A vulnerable server returned operating-system information and did not always write a file. Defenders should therefore treat apparent probes as meaningful evidence and search logs from every application node, especially behind load balancers.
Web shells support persistent, hands-on access
After confirming exposure, the operators either installed JSP web shells or executed commands directly in memory. A web shell provides a lasting command channel through the application server. In-memory execution may avoid creating a new file, reducing the visibility of file-focused defenses.
Some commands ran with root or SYSTEM privileges. Even where the application account was less powerful, it could still reach PeopleSoft configuration files and database connection details. Those assets can enable access to employee, payroll or student records and provide credentials for movement into connected systems.
On Windows hosts, the attackers used another web shell to transfer a trojanized installer in small pieces, helping it fit within request-size limits. The installer delivered the SIDEEYE backdoor in memory. Reported capabilities include stealing browser and desktop credentials, managing processes and files, opening an interactive reverse shell and establishing a proxy.
The campaign also used tunneling software to carry internal traffic through ordinary web connections. On Linux, operators deployed remote-management tooling for persistence. These actions show that the compromised PeopleSoft server is an entry point, not necessarily the final target.
Patching must replace temporary perimeter controls
Organizations should install Oracle’s security update for CVE-2026-35273 and keep PeopleTools on a supported version. Administrators should disable the Environment Management Hub when it is unnecessary or remove the affected application where operationally feasible.
- Search access logs for the encoded
/%50SEMHUB/route and related external POST requests. - Inspect PeopleSoft web directories for unapproved JSP, JSPX and executable files.
- Alert when the WebLogic Java process launches shells or unusual child processes.
- Review database audit logs for bulk exports and monitor large outbound transfers.
- Rotate application, database and service credentials exposed to a compromised host.
Treat any shell as a full compromise
Removing a visible JSP file is not enough. Responders should preserve forensic evidence, isolate affected nodes and examine adjacent servers, databases and identity systems for lateral movement. They must also hunt for memory-resident backdoors and tunneling utilities that can survive after the original shell disappears.
The incident is a broader warning about compensating controls. WAFs can reduce exposure while teams deploy an emergency update, but request parsing differences make them fragile as a permanent answer. Once active exploitation is confirmed, patching, threat hunting and credential containment need to move together.
Source: Cyber Security News coverage of Google Cloud threat research.
Leave a Reply
You must be logged in to post a comment.