ShinyHunters Beat PeopleSoft WAF Rules by Encoding One Letter in the URL
Security / news
ShinyHunters Beat PeopleSoft WAF Rules by Encoding One Letter in the URL
Mandiant says UNC6240 is back on CVE-2026-35273 with a request path that string-matching firewalls miss, and the only real fix is Oracle's June 10 patch.

Mandiant and Google Threat Intelligence Group said on Sept. 25 that the extortion crew ShinyHunters, tracked as UNC6240, is again mass-exploiting CVE-2026-35273 in Oracle PeopleSoft, this time by requesting /%50SEMHUB/ instead of /PSEMHUB/. The change of one letter, P written as %50, gets past web application firewall rules that block the literal path. Operators who relied on those rules rather than Oracle's patch remain exposed.
The flaw is an unauthenticated remote code execution bug in the Environment Management Hub (PSEMHUB) endpoint. Oracle issued an out-of-band Security Alert for it on June 10. Mandiant's renewed-campaign report dates the original zero-day exploitation to May 27 through June 9, aimed mostly at higher education.
Why the encoded path works
BleepingComputer, which reported the campaign on Sept. 26, explains the mechanism. Many firewalls compare the raw request path to a blocklist before decoding it. Oracle WebLogic decodes the path first and then routes it, so /%50SEMHUB/ reaches the same vulnerable servlet the rule was written to protect.
Mandiant's advice is to enforce blocking on normalised paths and to assume any percent-encoded, mixed-case or non-normalised variant of /PSEMHUB/ may be tried. It also wrote that "WAF rules and path-based blocking are not a substitute for patching."
What the attackers leave behind
Mandiant lists several payloads, all installed after code execution on the PeopleSoft web tier.
| File or tool | What it does |
|---|---|
x.jsp | Web shell taking hex-encoded commands over HTTP POST |
u.jsp, u2.jsp | Uploads files in 150 KB Base64 chunks, then runs them |
tunnel.jsp, tunnel.jspx | Neo-reGeorg tunnelling, SOCKS5 proxy over HTTP |
Ple64.exe | SIDEEYE backdoor in a trojanised Light Alloy player installer |
| MeshAgent | Legitimate remote-management tool, placed in /tmp on Linux |
SIDEEYE is a 5.2 MB binary signed with a valid EV certificate issued through Sectigo to "Tobias Weihmann Software Development OU", according to Mandiant. It steals browser and desktop-application credentials and calls out to 162.219.30.165 on TCP ports 3333 and 3334.
The report names seven sectors with victims: higher education, technology, IT services, healthcare, agriculture, transportation and government. It gives the count as "dozens of systems globally" and no precise total.
What to check on a PeopleSoft server
Mandiant's checklist, in the order it gives it:
- Apply the Oracle Security Alert for CVE-2026-35273, then disable the EMHub service or, on single-server setups, remove the PSEMHUB application.
- Search WebLogic access logs for
/PSEMHUB/and its percent-encoded forms, POST requests to/hubfrom outside, and JSP requests from external addresses. - Inspect the
PSEMHUB.wardirectory forx.jsp,u.jsp,tunnel.jsp,tunnel.jspxandPle64.exe. - Rotate database credentials in
psappsrv.cfg, Integration Broker credentials and any cloud credentials reachable from the web tier.
Mandiant also warns that UNC6240 "has a well-established pattern of data theft extortion", meaning stolen data is held for ransom on a leak site. Hosts where a web shell is found should be treated as compromised, and the report suggests hunting for large .tar, .tar.gz and .zst archives in temporary directories as evidence of theft.
Mandiant's June post on the original zero-day is linked from the September report. Elsewhere on this desk, Check Point's two 9.8-rated flaws and F5's BIG-IP APM zero-day are other exploited flaws in products that sit in front of internal systems.
Neither Mandiant nor BleepingComputer gives a figure for data stolen in the September wave. Oracle's alert of June 10 is still the only patch either names.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.