ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks

https://hackread.com/wp-content/uploads/2026/09/shinyhunters-bypass-waf-rules-oracle-peoplesoft-attacks.jpg

Mandiant and the Google Threat Intelligence Group (GTIG) have identified renewed exploitation of a critical Oracle PeopleSoft vulnerability, with attackers using a simple URL trick to bypass web application firewall (WAF) rules deployed against the flaw.

The activity is linked to UNC6240, aka ShinyHunters. The group exploited CVE-2026-35273 as a zero-day between May 27 and June 9. Oracle released an emergency security update on June 10; however, the latest activity is a continuation of this earlier campaign.

URL Encoding Defeats WAF Rules

The vulnerability affects PeopleSoft’s Environment Management Hub (PSEMHUB). In the latest campaign, attackers changed /PSEMHUB/ to /%50SEMHUB/, replacing the letter “P” with its URL-encoded equivalent.

For context, many WAF and reverse-proxy rules match the path before URL decoding, so they may not recognize the altered request. WebLogic then decodes the path and routes it to the vulnerable servlet, allowing exploitation to proceed.

Mandiant found web shells...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more