SHINYHUNTERS BYPASSES WAF RULES IN RENEWED ORACLE PEOPLESOFT ATTACKS

ShinyHunters has resumed widespread attacks against Oracle PeopleSoft servers, using a simple change to web requests to get past some web application firewall (WAF) rules. Mandiant and Google Threat Intelligence Group say the campaign targets systems that remain vulnerable to CVE-2026-35273, a critical PeopleTools flaw Oracle patched in June. Google Cloud Blog

How the PeopleSoft WAF bypass works

After the vulnerability became public, some organizations blocked requests to the affected /PSEMHUB/ path at their WAF. According to Mandiant, the attackers changed one character in that path to its URL-encoded form. Certain WAF rules checked the request before decoding it, while the PeopleSoft server decoded it and passed the request to the vulnerable component. That allowed attacks through defenses that appeared to block the original path. Google Cloud Blog

Mandiant says the renewed campaign has placed web shells on dozens of systems worldwide, including organizations in higher education, healthcare, government, technology, and transportation. Researchers also observed follow-on tools used for remote access and internal movement, including the SIDEEYE backdoor. Those findings describe systems Mandiant investigated; they do not establish that every targeted organization suffered data theft. Google Cloud Blog

What PeopleSoft administrators should do

Oracle says CVE-2026-35273 affects supported PeopleTools versions 8.61 and 8.62. The flaw can be exploited remotely without authentication and may lead to code execution. Organizations should apply Oracle’s security update promptly instead of relying on a WAF rule as their primary protection. CVE-2026-35273

Mandiant also advises administrators to review WebLogic access logs for requests to /PSEMHUB/ and encoded variations, inspect the PeopleSoft web directories for unexpected files, and investigate unusual remote management tools or outbound connections. If a web shell is found, the affected server should be treated as compromised and credentials accessible from it should be rotated.

Leave a Comment

Your email address will not be published. Required fields are marked *