Vulnerability

ShinyHunters revives PeopleSoft exploits with a simple URL‑encoding bypass

⏱️ 3 min read📅 9/27/2026👁️ 11 views

ShinyHunters revives PeopleSoft exploits with a simple URL‑encoding bypass

By slipping /%50SEMHUB/ past most web‑application firewalls, the ShinyHunters gang resurrected attacks on Oracle PeopleSoft that were thought to be dormant.

Why it matters

The trick reaches the vulnerable PeopleSoft Environment Management Hub (PSEMHUB) endpoint before the firewall gets a chance to block it, effectively bypassing a layer of defense that many organisations rely on.

Technical walk‑through

Google’s Threat Intelligence Group and Mandiant observed the following chain:

  • Oracle WebLogic decodes the percent‑encoded character before routing, while many WAFs and reverse proxies compare the raw path first. The mismatch lets /%50SEMHUB/ be treated as /PSEMHUB/.
  • Attackers fire 5‑15 POST requests to /%50SEMHUB/hub containing serialized Java objects. The payload probes the system without writing files and returns the host’s operating‑system details.
  • When the probe confirms the CVE‑2026‑35273 RCE flaw, the gang drops JSP web shells: x.jsp for command execution, u.jsp or u2.jsp for file upload.
  • A Windows executable named Ple64.exe, identified as the SIDEEYE backdoor, is also installed. SIDEEYE steals credentials, manipulates processes/files, and offers reverse‑shell and reverse‑proxy capabilities.
  • To tunnel traffic, they serve the open‑source Neo‑reGeorg toolkit via tunnel.jsp or tunnel.jspx, turning HTTP/HTTPS into a SOCKS5 proxy.
  • On Linux hosts they sometimes leverage legitimate MeshAgent remote‑management software to keep a foothold.

Who’s at risk

Any organisation running unpatched Oracle PeopleSoft—whether on Windows or Linux—could be hit. Google’s report lists dozens of compromised systems across higher‑education, technology, IT services, healthcare, agriculture, transportation and government sectors.

Defensive steps

Patch first. Oracle’s security update for CVE‑2026‑35273 is publicly available and should be applied immediately.

  1. Audit WAF rules: ensure they inspect the request after URL decoding, or add explicit blocks for the percent‑encoded variant.
  2. Monitor web‑server logs for the “/%50SEMHUB” pattern or for a burst of POST requests to the PSEMHUB endpoint.
  3. Search for known web‑shell filenames (x.jsp, u.jsp, tunnel.jsp) and for the SIDEEYE executable Ple64.exe on both Windows and Linux hosts.
  4. Validate that MeshAgent instances are authorised; any rogue installations may indicate post‑exploitation activity.
  5. Consider network‑level segmentation for PeopleSoft components to limit lateral movement.

Even with the update, keep an eye on anomalous traffic patterns—attackers often pivot to new encoding tricks once a rule is closed.

#PeopleSoft#ShinyHunters#WAF bypass#CVE-2026-35273#web shells