ShinyHunters Exploits Critical Oracle PeopleSoft Flaw to Deploy Web Shells via WAF Bypass
Threat group UNC6240, linked to ShinyHunters, has been actively exploiting a critical pre-authentication remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62, according to a September 25, 2026 report by Google Threat Intelligence Group and Mandiant. Attackers bypass web application firewalls by percent-encoding the letter 'P' in the target URL path as '%50', causing WAF string-matching rules to miss the request while the backend WebLogic server decodes and processes it normally. JSP web shells have been confirmed on dozens of compromised systems, with some intrusions also involving fileless command execution that leaves no shell files on disk. Following initial access, attackers deployed multiple post-intrusion tools including SIDEEYE for credential theft, Neo-reGeorg for internal SOCKS tunneling, and MeshAgent for remote management on Linux hosts. Oracle has issued a security advisory, and organizations running affected PeopleSoft versions are urged to apply patches and review WAF rules to detect encoded URI variants.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in