VMTech
Discuss a project →

Google Warns of WAF Bypass in Oracle PeopleSoft Exploitation

Google Warns of WAF Bypass in Oracle PeopleSoft Exploitation

Google has warned of renewed mass exploitation of CVE-2026-35273, a critical Oracle PeopleSoft vulnerability with a CVSS score of 9.8. The flaw can enable unauthenticated remote code execution, and Mandiant says the latest activity linked to UNC6240 has affected organisations across higher education, technology, IT services, healthcare, agriculture, transportation and government.

The attackers have deployed web shells on dozens of systems. Their updated technique is notable because it evades web application firewall rules intended to block access to the vulnerable PeopleSoft Environment Management Hub endpoint, PSEMHUB.

An encoded path defeats literal WAF matching

Mandiant said UNC6240 modified its exploit to request /%50SEMHUB/ instead of /PSEMHUB/, URL-encoding the letter P as %50. Many WAF and reverse-proxy rules compare the literal request path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet.

The campaign identifies susceptible hosts with POST requests to /%50SEMHUB/hub containing a serialized Java object. It then abuses Java deserialization in the PSEMHUB hub servlet to achieve fileless command execution and place web shells.

Web shells, backdoors and elevated execution

Two JSP files are dropped in the PSEMHUB.war directory to reduce WAF visibility during post-exploitation. The x.jsp shell supports cross-platform command execution. The u.jsp shell supports chunked uploads and command execution through cmd.exe.

Using u.jsp, the operators upload a valid signed but trojanized installer named Ple64.exe. It loads the SIDEEYE C++ backdoor in memory. Google said SIDEEYE communicates with an external server over TCP and provides credential theft from browsers and desktop applications, process and file management, an interactive reverse shell and reverse-proxy capabilities.

The operators also staged the open-source Neo-reGeorg tunnelling toolkit. On Linux, they used the legitimate remote-management tool MeshAgent to establish persistent access after web-shell placement. About one quarter of observed commands ran as root or NT Authority\SYSTEM; the others ran under PeopleSoft or WebLogic service accounts.

Containment priorities for PeopleSoft operators

Oracle PeopleSoft operators should apply patches for CVE-2026-35273 and disable EMHub in multi-server deployments or remove the PSEMHUB application in single-server deployments. Teams should search WebLogic access logs for /PSEMHUB/ requests and percent-encoded variants, then inspect PSEMHUB.war for JSP shells and other malicious artifacts.

Google also recommends rotating credentials accessible to the PeopleSoft application service account, hunting PeopleSoft and database hosts for large archives in temporary or web-accessible locations, reviewing database audit logs for bulk queries or exports involving HR, payroll and student-record tables, and monitoring outbound traffic. Because UNC6240 has a pattern of data-theft extortion, a practical business response is to combine rapid patching and endpoint investigation with credential containment and preparation for possible exposure or extortion communications.

#cybersecurity#peoplesoft#wafsecurity#vulnerability
Open analytics
On the site 3 views
min read 4 26.09.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Google Warns of WAF Bypass in Oracle PeopleSoft Exploitation

Open the post on Instagram ↗