ShinyHunters bypasses WAFs to exploit Oracle PeopleSoft flaw

 

ShinyHunters bypasses WAFs to exploit Oracle PeopleSoft flaw

The ShinyHunters extortion group is using a URL-encoding trick to bypass web application firewalls (WAFs) and exploit a critical Oracle PeopleSoft vulnerability, tracked as CVE-2026-35273.

CVE-2026-35273 allows unauthenticated remote code execution on vulnerable servers.

Google’s Mandiant and Threat Intelligence Group (GTIG) said the attackers are targeting PeopleSoft servers that have not installed Oracle’s security update. Organizations that tried to block the vulnerable /PSEMHUB/ endpoint with WAF rules may still be exposed.

The attackers have modified the exploit to use encoded paths such as /%50SEMHUB/. Some WAFs check the request before decoding the URL, allowing the malicious request to bypass the security rule. The PeopleSoft server can then decode the path and route it to the vulnerable endpoint.

Google said ShinyHunters, tracked by Mandiant as UNC6240, has compromised dozens of systems worldwide across sectors including higher education, healthcare, technology, government, and transportation.

After gaining access, the attackers have deployed JSP web shells, malware, and tunneling tools to maintain access and move through internal networks.

Mandiant recommends installing the latest Oracle security update rather than relying on WAF rules to protect against CVE-2026-35273. Organizations should also review WebLogic logs for requests to /PSEMHUB/ and encoded versions such as /%50SEMHUB/, which could indicate attempted exploitation.

Back to the list