Vulnerabilities — Threats
ShinyHunters Uses Encoding Trick to Re-Exploit Oracle PeopleSoft Flaw Past WAFs
One URL-encoded letter lets ShinyHunters walk around web application firewall rules blocking its favorite attack path — re-targeting servers that blocked the endpoint with WAFs instead of patching. Mandiant confirmed the flaw was exploited as a zero-day in May and June.
Photo: DronePhotographer, CC0, via Wikimedia Commons
ShinyHunters has revived its campaign against Oracle PeopleSoft with a modified exploit that bypasses web application firewall rules using a single encoded character — turning a patched-in-June flaw back into a live threat for organizations that chose blocking over fixing.
The flaw, CVE-2026-35273, is a critical (CVSS 9.8) Java deserialization vulnerability in Oracle PeopleSoft’s Environment Management Hub (PSEMHUB) that allows unauthenticated remote code execution. Google Mandiant and the Google Threat Intelligence Group (GTIG) reported Sept. 25 that UNC6240 — Google’s designation for ShinyHunters — exploited it as a zero-day between May 27 and June 9, 2026: “Because this activity predates Oracle’s June 10, 2026 advisory, the vulnerability was exploited as a zero-day.” Attackers planted web shells on dozens of systems globally; Mandiant notified more than 100 organizations, roughly two-thirds of them in higher education.
Oracle shipped an emergency Security Alert on June 10. Named victims in reporting include the University of Nottingham, the insurance regulator NAIC, and Nissan. Compromised organizations experienced data theft, with stolen data published on the ShinyHunters data-leak site.
Photo: Håkan Dahlström, CC BY 2.0, via Wikimedia Commons
The encoding trick
In the renewed wave, the group modified its exploit to use URL encoding — requesting /%50SEMHUB/ instead of /PSEMHUB/. WAF rules that match the literal path before decoding never fire, while Oracle WebLogic decodes the encoded ‘P’ and routes the request to the vulnerable endpoint. The result: servers that blocked the endpoint with a WAF instead of patching are exploitable again. HaveIBeenPwned has indexed 455,000 emails from the PeopleSoft breach fallout.
Confirmed vs. alleged
Confirmed: Mandiant/GTIG’s attribution of zero-day exploitation of CVE-2026-35273 to UNC6240/ShinyHunters in May–June 2026, Oracle’s June 10 emergency Security Alert, and the WAF-bypass technique. Alleged: SecurityWeek reports the ShinyHunters hack of the FBI jobs portal — see our companion report on the arrests — likely used a modified exploit for this CVE. That role is a press report, not a confirmed finding.
What we know
- CVE-2026-35273 (CVSS 9.8) is a Java deserialization flaw in PeopleSoft’s Environment Management Hub allowing unauthenticated RCE.
- Google Mandiant/GTIG confirmed UNC6240 (ShinyHunters) exploited it as a zero-day May 27–June 9, 2026, planting web shells on dozens of systems; 100+ organizations were notified.
- The renewed exploit variant uses URL encoding (
/%50SEMHUB/) to bypass WAF rules that match the literal path before decoding. - Oracle’s advisory calls implementing its mitigations “a high-priority risk reduction measure” and “strongly recommend[s] immediate action to address the identified exposure.”
What remains unknown
- The full victim count: ShinyHunters’ claims of 300+ instances and 100+ organizations sit alongside Mandiant’s 100+ notified organizations — unresolved.
- The extent of the renewed WAF-bypass wave is still developing.
- The CVE’s role in the FBI jobs-portal hack is alleged (SecurityWeek), not confirmed.
What you can do
- Patch, don’t just block. Apply Oracle’s June 10 Security Alert immediately — WAF rules matching the literal path are insufficient.
- Fix WAF rules properly. Any rules for the PSEMHUB endpoint must decode percent-encoded URLs before matching, or the encoding bypass works.
- Hunt, don’t assume. Organizations running PeopleSoft through the May–June zero-day window should hunt for web shells and unauthorized access even if no WAF alerts fired.
Corrections: No corrections have been published for this article.
Related coverage
About the author
Exploitation intel, as it lands
Get HackedWire’s threat-intelligence coverage in your inbox. Subscribe to the newsletter →