Oracle PeopleSoft Exploitation: How One Encoded Character Bypassed a WAF Rule
A URL-encoded P let UNC6240 evade literal-path WAF rules at Oracle PeopleSoft. Netics examines the patch-first response to renewed CVE-2026-35273 exploitation.
TL;DR
- On September 25, 2026, Mandiant and Google Threat Intelligence Group (GTIG) reported renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), following the June 2026 campaign that used the flaw as a zero-day against education.
- The bypass is one URL-encoded character: the actor requests /%50SEMHUB/ instead of /PSEMHUB/, because many WAF and proxy rules match the literal path before URL decoding.
- Web shells landed on dozens of systems globally — higher education, technology, IT services, healthcare, agriculture, transportation, and government.
- A typical probe is five to 15 POST requests carrying a serialized Java object; unpatched servers answer with the host operating system and the check stays silent.
- This is a renewal, not a first sighting: the June wave hit education as a zero-day, and Oracle patched on June 10, 2026.
- The post-exploitation chain includes JSP shells, fileless command execution, SIDEEYE via Ple64.exe, Neo-reGeorg tunnels, and MeshAgent persistence; hunt the whole path, not just files.
- Patch first: WAF rules and path-based blocking are not a substitute for patching. Hunt encoded variations and unexpected .jsp files; rotate credentials as if the host were already compromised.
A renewed campaign aimed at every sector
On September 25, 2026, Mandiant and Google Threat Intelligence Group published the follow-up report, ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft, on the Google Cloud blog. CVE-2026-35273, the Java deserialization flaw in Oracle's Environment Management Hub (PSEMHUB), is being mass-exploited again by UNC6240 (ShinyHunters). What changed since June is not the vulnerability: the actor modified its exploit to bypass the web application firewall (WAF) rules deployed against the endpoint.
The mechanism is quietly brutal. The actor requests /%50SEMHUB/ in place of /PSEMHUB/, and the report explains why that defeats a rule: "Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet." A rule that matches a string can be bypassed by a request that is not the string and yet is the same path. Scope grew with technique: GTIG shows the actor "deploying web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government". The education-only focus of June is gone.

A one-character encoding that defeats a literal-path rule
%50 is the URL-encoded form of the letter P. WebLogic decodes /%50SEMHUB/ back into /PSEMHUB/ and serves the application normally; a rule that matches the literal string /PSEMHUB/ before decoding never sees the match. GTIG's warning covers the whole class of variants: "Defenders should assume that threat actors may use any percent-encoded, mixed-case, or otherwise non-normalized variant of /PSEMHUB/, and should enforce blocking on the normalized path."
The uncomfortable part is how foreseeable this was. The June guidance already recommended blocking external access to /PSEMHUB/* at the perimeter while "noting that WAF body-inspection rules alone were insufficient." The September post states the consequence: "The current campaign demonstrates that UNC6240 adapted to published defensive guidance, targeting organizations that implemented WAF rules but did not patch the vulnerability." At each inspection boundary, normalize the path before matching it; otherwise the rule and the application may evaluate different representations of the same request.
GTIG's own quick guide is unambiguous: "WAF rules and path-based blocking are not a substitute for patching." That sentence is the story of this wave. A WAF rule is a mitigation with a lifespan: it expresses a string match at one point in the request pipeline, and the application server downstream may normalize the same request differently. Patching removes the component the request addresses — no encoding variant helps once the servlet is gone. This is the same controls-versus-conditions lesson we drew from the September GitLab mass exploitation of CVE-2026-85706: a rule that an attacker can normalize around is a condition, not a control.

The probe that confirms quietly before anyone owns the host
Before exploitation, the pattern is consistent. GTIG observed that "targeted servers typically received five to 15 POST requests to /%50SEMHUB/hub containing a serialized Java object." Unpatched servers respond "without writing files or disrupting the service, allowing the threat actor to quietly confirm exploitability." On hosts validated but not yet exploited, "organizations may see this request in logs, with no follow-on activity." The asymmetry is the operational point: the probe is short, silent, and leaves no file behind — it is visible only to a team that actually reads access logs.
Two exploitation methods follow, both abusing Java deserialization in the PSEMHUB hub servlet. The first is web shell deployment: a burst of POSTs to /%50SEMHUB/hub followed by JSP files such as x.jsp in PSEMHUB.war, repeated so every node behind a load balancer receives a copy. The second is fileless command execution: POSTs that return command output directly in the HTTP response, with nothing written to disk. "Detections that rely on JSP file creation will not identify this method", the report warns — the hunt has to look for shell processes (cmd.exe or /bin/sh) spawned by the WebLogic Java process, not just new files.

What the shell opens once it lands
Post-exploitation stops being PeopleSoft-specific. The primary shell x.jsp takes hex-encoded commands via POST and returns output prefixed with R:. A second servlet, u.jsp, decodes Base64 chunks in 150 KB increments to stage larger binaries while bypassing HTTP request-size limits. On Windows hosts the actor uploaded Ple64.exe, a 5.2 MB binary masquerading as a signed Light Alloy media player installer but carrying a three-stage chain that loads the SIDEEYE backdoor in memory; the sample was signed with a valid EV certificate issued to Tobias Weihmann Software Development OU via Sectigo. Alongside it came the Neo-reGeorg tunneling servlets tunnel.jsp and tunnel.jspx, routing SOCKS5 proxy traffic through ordinary HTTP for internal discovery and lateral movement.
On Linux, persistence runs through MeshAgent, a legitimate remote management tool: binaries and configuration land in /tmp (meshagent, meshagent.msh, meshagent.db) under the PeopleSoft service account, with outbound connections to Microsoft-masquerading domains including azurenetfiles.net. MITRE's mapping is familiar — T1190 (exploit public-facing application), T1505.003 (web shell), T1048 (exfiltration over alternative protocol). The consequence is blunt: a quarter of observed commands executed as root or NT Authority\SYSTEM. Where a shell is found, GTIG is unambiguous: organizations should "treat the host as compromised, preserve evidence, and rotate all credentials accessible from the PeopleSoft tier".

Patch, disable EMHub, rotate credentials, watch the egress
The remediation guide is short. Apply the Oracle Security Alert patch for CVE-2026-35273. Disable EMHub in multi-server configurations, or remove the PSEMHUB application entirely in single-server ones; EMHub and the Integration Broker listening connector are administrative, system-to-system components, and restricting them from the public internet does not break standard PeopleSoft Internet Architecture sessions. Search PIA WebLogic access logs for /PSEMHUB/ and any percent-encoded variant, POSTs to /hub from external sources, and unexpected .jsp or .jspx files. Check every node, not only the first identified, because the burst exists precisely to replicate shells across load-balanced nodes. Inspect PSEMHUB.war for non-shipped files, rotate credentials readable by the application service account — psappsrv.cfg connection strings, Integration Broker credentials, cloud credentials — and monitor outbound traffic. "UNC6240 has a well-established pattern of data theft extortion," so prepare for extortion communications.
A renewal, not a first sighting
Honesty requires the counterpoints, because they are present in the source. This is a renewal, not a first sighting: the June wave exploited the CVE as a zero-day between May 27 and June 9, 2026, predominantly against higher education, and Oracle shipped an out-of-band Security Alert on June 10, 2026. Organizations that followed the June guidance and disabled EMHub have no servlet left to probe this September — the campaign primarily bites teams that chose a WAF rule over the patch.
Mass-exploitation economics are why the response has to be mechanical: a low-noise probe, a confirmation that writes nothing, a persistence toolkit that survives the web tier. The patch is the only control that closes the CVE; logs, endpoint checks, and egress review are the detection layer, valuable only while the window is still open. Check your access logs for /%50SEMHUB/ tonight, whatever your WAF vendor promised. New threat-intelligence breakdowns land on neticslabs.com.
Sources
Source: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft — cloud.google.com/blog, 2026-09-25. June 2026 companion post (source of the extortion-notice figure): ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit — cloud.google.com/blog, June 2026. Network, host, and file indicators (including 5.199.162.157, 104.219.234.138, winmanage-me.network) and the MITRE ATT&CK mapping come from the IOC tables in the September 2026 post itself.
Source: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft — cloud.google.com/blog, 2026-09-25, plus the June 2026 companion post for the extortion-notice figure.