The ShinyHunters WAF bypass targeting Oracle PeopleSoft has resumed widespread exploitation, with the extortion gang now using a URL-encoding trick to slip past the firewall rules that organisations had deployed as a temporary shield against CVE-2026-35273. Google’s Mandiant and Threat Intelligence Group (GTIG) published a new assessment confirming the technique, and warning that patch installation (not WAF rules) is the only reliable protection.

How the ShinyHunters WAF bypass PeopleSoft trick works

The vulnerability at the centre of this campaign is CVE-2026-35273, rated CVSS 9.8. According to Decryption Digest, it is an unauthenticated server-side request forgery to remote code execution chain affecting Oracle PeopleTools versions 8.61 and 8.62. Oracle fixed the flaw the day after BleepingComputer first reported it on 10 June, describing it as allowing unauthenticated remote code execution.

At the time of that fix, Mandiant advised organisations that could not immediately apply the patch to block external access to the vulnerable /PSEMHUB/* endpoint via a web application firewall (WAF). ShinyHunters has now made that advice largely obsolete. Instead of sending requests to /PSEMHUB/, the attackers are routing them to /%50SEMHUB/, where %50 is the percent-encoded form of the letter ‘P’.

The problem, as Mandiant explains, is that many WAFs and reverse proxies compare the literal request path before decoding it. A rule blocking /PSEMHUB/ simply does not see /%50SEMHUB/ as a match. Oracle WebLogic, on the other hand, decodes the encoded character and routes the request to the vulnerable endpoint regardless. ‘This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,’ Mandiant states.

Google also cautions that %50 is only one option. ShinyHunters could rotate to other percent-encoded characters, mixed-case variants, or alternative encodings of the same path to stay ahead of any rule written to catch this specific bypass.

Scale of compromise and attack chain detail

The scale of the campaign is considerable. Arctic Wolf reports that ShinyHunters claims to have already compromised 300 instances across more than 100 organisations. The new wave of attacks following the WAF bypass has deployed web shells on dozens of additional systems worldwide, spanning higher education, technology, IT services, healthcare, agriculture, transportation and government organisations, according to Google.

The attack sequence follows a consistent pattern. Before attempting full exploitation, the attackers typically send between five and 15 POST requests to /%50SEMHUB/hub containing serialised Java objects. On vulnerable systems, those requests return information about the host operating system without writing files or disrupting the service, a quiet reconnaissance pass that lets ShinyHunters assess exploitability before committing to a full attack.

Once a system is confirmed vulnerable, the threat actors exploit the flaw again to execute commands directly in memory or deploy JSP web shells. Google says the attackers use an x.jsp shell for command execution and u.jsp and u2.jsp shells for uploading larger files. On compromised Windows servers, those shells have been used to deploy an executable named Ple64.exe, which masquerades as a signed Light Alloy media player installer but installs a backdoor Google tracks as SIDEEYE. SIDEEYE is used to steal credentials, manage processes and files, create interactive reverse shells, and provide reverse proxy functionality.

The group has also deployed the open-source Neo-reGeorg tunnelling toolkit via tunnel.jsp and tunnel.jspx files, which tunnels SOCKS5 proxy traffic over normal HTTP and HTTPS connections, letting a compromised PeopleSoft server become a pivot point into the wider internal network. On Linux systems, Mandiant observed ShinyHunters using the legitimate MeshAgent remote management software to maintain persistent access.

The FBI Jobs claim and what remains unverified

These attacks arrive in the wake of ShinyHunters’ claim (told to BleepingComputer on 22 September) that they breached FBI systems using what they described as a new Oracle PeopleSoft zero-day. The group alleged the vulnerability allowed remote code execution and was used to access the FBI Jobs platform before spreading laterally into the FBI’s AWS GovCloud infrastructure. ShinyHunters claimed to have stolen between 2TB and 3TB of data related to current and former FBI employees, job applicants and other internal systems.

BleepingComputer stated at the time that it could not independently verify the alleged zero-day, the claimed lateral movement, or the volume of data reportedly stolen. The FBI confirmed it was investigating claims of unauthorised activity affecting FBIjobs.gov but did not confirm a breach or that any data was taken. ShinyHunters has since told BleepingComputer that the WAF bypass was used against FBI Jobs, while continuing to claim they also exploited a ‘NEW unknown vulnerability in the same PSEMHUB component’, an assertion that remains unverified.

Mandiant’s immediate advice to organisations running Oracle PeopleSoft is direct: install the latest security update. As a detection measure, administrators should search WebLogic access logs for requests to /PSEMHUB/ and encoded variants such as /%50SEMHUB/. A WAF rule is not a substitute for patching when the attackers have already demonstrated they can route around it.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version