Exploiting vulnerabilities in Oracle PeopleSoft systems to hide a web presence
They are installing hidden web shells by exploiting weaknesses in Oracle PeopleSoft systems!
New attacks have been identified against Oracle PeopleSoft systems. Experts have determined that attackers are exploiting the critical vulnerability CVE-2026-35273. Attackers attempted to bypass security rules by sending the vulnerable path in a different form, which was initially blocked by WAF. As a result, hidden web shells, remote control tools, and other malicious components were discovered on some affected servers.
New attacks observed in September 2026 covered a wider scope than previous situations. This included technology and IT services, healthcare, agriculture, transportation, government agencies, and higher education institutions.
This situation demonstrates that relying solely on security measures like WAF is not enough. Although some organizations blocked access to a vulnerable endpoint via WAF, the main vulnerability was not eliminated. Attackers succeeded in bypassing existing protection rules by modifying the request format.
For this reason, organizations using Oracle PeopleSoft systems are advised to fix the CVE-2026-35273 vulnerability, install security updates in a timely manner, and investigate suspicious activities on servers.
What danger does CVE-2026-35273 pose?
CVE-2026-35273 is a critical vulnerability in the Environment Management component of the Oracle PeopleSoft PeopleTools product, which allows access without authentication over the network.
Oracle assigned a CVSS score of 9.8 to this vulnerability. If successfully exploited, attackers can execute code and take over the PeopleSoft environment remotely. The vulnerability affects PeopleTools versions 8.61 and 8.62.
The problem is particularly dangerous because PeopleSoft systems can be linked to an organization's important business processes. Specifically:
- employee and personnel data;
- payroll and financial information;
- student information;
- database connection settings;
- inter-system integration data;
- the organization's internal information resources.
Therefore, the compromise of a PeopleSoft server can lead to much more serious consequences than a simple website compromise.
The vulnerability was initially exploited as a zero-day.
The risk for this vulnerability was particularly relevant in June 2026. Mandiant and Google Threat Intelligence Group identified that CVE-2026-35273 was actively exploited between May 27 and June 9, 2026.
The main targets of these attacks were higher education institutions. Since the vulnerability had not yet been officially announced by Oracle, this activity was assessed as zero-day exploitation. Oracle issued a Security Alert regarding this vulnerability on October 10, 2026.
After the initial attacks, organizations began blocking the vulnerable endpoint through WAF and other perimeter protection measures.
However, this did not lead to a long-term solution.
How did attackers bypass WAF protection?
The most important aspect of the new wave of attacks was the exploitation of the difference between the WAF rules and the PeopleSoft server's request processing mechanism.
For example, the protection system might block the path:
/PSEMHUB/
The attacker then sent a single character of this path in URL encoding:
/%50SEMHUB/
Here, %50 is the URL-encoded form of the letter "P".
As a result, some WAF or reverse-proxy systems checked the request before it was decoded and did not find the /PSEMHUB/ line. The PeopleSoft/WebLogic server then decoded the request and redirected it to the actual /PSEMHUB/ endpoint.
Simply put:
WAF:
"This is not /PSEMHUB/, so I will not block it."
PeopleSoft server:
"This is actually /PSEMHUB/."
In this way, the attacker was able to bypass the external defense layer and access the vulnerable component.
This situation also shows the risk of creating WAF rules based only on text matching.
The attack started with testing.
According to Google Threat Intelligence data, attackers usually tested the server before exploitation.
In some cases, 5–15 POST requests were sent to the address /%50SEMHUB/hub. These requests contained information related to Java object serialization.
If the server is vulnerable, it might return operating system-related information. Importantly, such testing does not always lead to writing files to the server or the system behaving in a way that is visible to the eye.
Therefore:
"No malicious files were found on the server" does not mean the attack did not happen.
Especially if shell processes like cmd.exe, /bin/sh, or other shell processes are running from the WebLogic process, this requires serious investigation.
Attackers can install web shells after exploitation.
In the next stage of exploitation, it was observed that attackers installed a JSP-based web shell on the server.
A web shell is a malicious software component installed on the server that allows an attacker to execute commands remotely.
In this campaign, the following files were identified:
x.jsp
u.jsp
tunnel.jsp
tunnel.jspx
Ple64.exe
Some of these were used to execute commands, while others were used to transfer files, create tunnels, or launch subsequent malicious components.
Attackers also attempted to install web shells on multiple server nodes in infrastructures that use load balancers. Therefore, it is not enough to check only a single PeopleSoft server—all WebLogic nodes must be checked.
Fileless attacks were also identified.
Another dangerous aspect of this campaign is that attackers never wrote files to the disk.
In some cases, commands were executed directly in memory. In such situations, ordinary antivirus or checks like "Did a new JSP file appear?" may not detect the attack.
For example, the execution of shell processes of the following types from the WebLogic Java process is considered suspicious:
cmd.exe
;/bin/sh
;bash
.
Therefore, process activity must also be monitored alongside the file system.
SIDEEYE and Remote Control Tools
After gaining initial access, attackers installed additional malicious tools in the next stage.
A trojanized installer leading to a SIDEEYE backdoor was identified on Windows systems. This could allow interaction with processes and files on the system, modification of authentication information, and remote interactive access capabilities.
On Linux systems, attackers attempted to maintain long-term access on the server by using remote control infrastructures like MeshCentral/MeshAgent. According to Google data, in the activity in September 2026, winmanage-me.network domain was linked to the MeshCentral infrastructure.
The important point here is that MeshCentral is a legitimate remote management platform. However, using legitimate applications for illegitimate purposes can make it difficult to detect the attack.
The compromise of a single PeopleSoft server does not end the danger.
After gaining access to the PeopleSoft server, attackers can look for ways to move to other systems present there.
According to Google Threat Intelligence observations, in some cases, the executed commands were performed with root or NT AUTHORITY\SYSTEM privileges. The rest of the activity was carried out through PeopleSoft or WebLogic service accounts.
Even if the privileges of a service account are restricted, it can have access to:
- PeopleSoft configuration files;
- database connection information;
- integration accounts;
- application data.
Therefore, if a web shell is found on a PeopleSoft server, it is not correct to view it only as a "web application issue." This incident must be investigated as a full server compromise.
What information is at risk?
Since PeopleSoft is used in many organizations to manage important business processes, the consequences of such a compromise may not be limited to the server itself.
The list of potential information at risk includes:
- personal and service information of employees;
- payroll and financial information;
- student information;
- internal databases;
- inter-system integration data;
- service accounts and passwords;
- access to other internal information resources.
Furthermore, there have been cases involving the theft and subsequent use of data in the ShinyHunters' activities.
What should organizations focus on?
Based on recommendations from Oracle and Google Threat Intelligence, organizations using PeopleSoft should take the following measures:
1. Install security updates for CVE-2026-35273
The most important measure is to install the security update provided by Oracle as soon as possible.
Blocking via WAF cannot replace a patch.
Oracle announced and recommended installing the security update for CVE-2026-35273 on October 10, 2026, as a measure to reduce high-priority risks.
2. Disable Environment Management Hub if not needed
In accordance with Oracle's recommendation, the unused Environment Management Hub (EMHub) service should be shut down or the PSEMHUB application should be removed from the relevant configuration.
3. Do not only link WAF rules to plain text
Monitoring and blocking mechanisms:
It is necessary to consider URL-encoded, registered, or other normalized variants of /PSEMHUB/ along with it.
Specifically:
Requests like /%50SEMHUB/ need to be checked separately.
4. Check WebLogic logs
Particular attention is advised to the following situations:
- Requests to /PSEMHUB/;
- URL-encoded variants of /PSEMHUB/;
- POST requests from external IP addresses;
- Unusual requests to the /hub endpoint;
- Unknown .jsp or .jspx files in the PSEMHUB catalog;
- Execution of shell processes from the WebLogic Java process.
5. Check all WebLogic nodes
If load balancing is used in an organization, checking only a single server is not enough.
Web shells may be deployed on other nodes as well.
6. Update service account passwords
If there is a possibility of compromise, authentication information used by PeopleSoft service accounts may need to be updated:
- database accounts;
- Integration Broker accounts;
- confidential information in configuration files;
- authentication information for other services and cloud accounts.
IoC: Technical Indicators for Detection
Some indicators linked to this campaign by Google Threat Intelligence are as follows:
| Type | Indicator | Note |
|---|---|---|
| IPv4 | 5.199.162.157 | Attack control, scanning, and HTTP callback |
| IPv4 | 104.219.234.138 | Data exfiltration/staging and remote control |
| IPv4 | 162.219.30.165 | C2 for SIDEEYE |
| Domain | winmanage-me.network | Related to staging and MeshCentral infrastructure |
| URI | /%50SEMHUB/ | Path observed when bypassing WAF |
| File | x.jsp | Main web shell |
| File | u.jsp | File transfer and execution component |
| File | Ple64.exe | Component related to SIDEEYE |
| File | tunnel.jsp | Neo-reGeorg tunnel component |
| File | tunnel.jspx | Neo-reGeorg JSPX tunnel component |
SHA-256
48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494
—x.jsp
2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7
—u.jsp
419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86
—tunnel.jsp
ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07
—tunnel.jspx
3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3
—Ple64.exe
It is recommended to check the IoCs in SIEM, EDR/XDR, IDS/IPS, WAF, and other monitoring tools.
ShinyHunters' new attacks against Oracle PeopleSoft systems show an important lesson: perimeter defenses cannot replace vulnerabilities.
Initially, organizations tried to limit the attack by blocking the /PSEMHUB/ endpoint via WAF. However, attackers succeeded in bypassing some protection rules by URL-encoding only a single character of the request. As a result, the possibility of re-attacking PeopleSoft systems that were previously thought to be protected arose.
This means that relying only on WAF rules is dangerous in PeopleSoft environments where the CVE-2026-35273 vulnerability exists. Organizations must install security updates, disable unused PSEMHUB/EMHub components, retrospectively check WebLogic logs, search for web shells on all server nodes, and investigate the incident fully if signs of compromise are detected. Oracle also recommends using supported PeopleTools versions and not delaying security updates.
Important: If any of the above IoCs are detected or suspicious requests like /%50SEMHUB/ are recorded in a PeopleSoft system, it is necessary to investigate for signs of compromise not just by deleting the file, but also in the server, service accounts, database connections, and other related systems.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.