News / Cybersecurity
ShinyHunters Bypasses WAFs to Exploit a Critical Oracle PeopleSoft Vulnerability (CVE-2026-35273) Published on 28 September 2026 by Christ-loisele (3 min read)
The ShinyHunters group (UNC6240) is exploiting an unpatched Oracle PeopleSoft vulnerability through URL-encoded requests, deploying web shells and backdoors such as SIDEEYE. Mandiant warns of attacks targeting both public and private sectors, including a claimed breach at the FBI.
A critical flaw exploited despite patches being available
ShinyHunters, also tracked as UNC6240, has resumed attacks against Oracle PeopleSoft servers by bypassing WAF (Web Application Firewall) rules using a URL encoding trick. According to BleepingComputer , the group uses requests like /%50SEMHUB/ to reach the vulnerable endpoint /PSEMHUB/, normally blocked. Oracle had patched this flaw, identified as CVE-2026-35273 , on June 10, 2026, enabling unauthenticated remote code execution.
The vulnerability, rated with a CVSS score of 9.8 by The Hacker News , is exploited via POST requests to /%50SEMHUB/hub containing a serialized Java object, thus abusing the Java deserialization mechanism integrated into Oracle WebLogic. Mandiant emphasizes that this technique allows attackers to compromise systems whose administrators believed their WAF rules were sufficient for protection.
This technique allows attackers to compromise systems whose administrators believed their WAF rules were sufficient for protection
Photo: ShinyHunters guruhi 10 ta kompaniya maxfiy ma'lumotlarini buzib kirgan hamda sotuvga qo'ygan (Optima D, CC BY-SA 4.0)
A sophisticated attack chain: web shells, backdoors, and lateral movement
Once access is gained, ShinyHunters deploys web shells (notably x.jsp and u.jsp) in the PSEMHUB.war directory to execute arbitrary commands and download files. The u.jsp is notably used to install a fake program, Ple64.exe, presented as a multimedia player but which actually loads the SIDEEYE backdoor, according to Mandiant’s analysis. This malware, used for credential theft, process management, and establishing reverse shells , communicates with the IP 162.219.30[.]165.
To maintain persistence in compromised networks, the group uses the Neo-reGeorg tool to create SOCKS5 tunnels, facilitating lateral movement. On Linux systems, MeshAgent is deployed to ensure persistence. Approximately 25% of the commands executed run with elevated privileges (root or NT Authority\[SYSTEM\]), giving attackers full control over the targeted machines.
A claimed FBI breach and diverse sectoral targets
ShinyHunters claims to have compromised the FBIJobs.gov portal by exploiting another zero-day flaw in Oracle PeopleSoft, separate from CVE-2026-35273. The group claims to have stolen between 2 and 3 terabytes of sensitive data hosted on the FBI’s AWS GovCloud infrastructure, aiming to contest accusations brought against them. According to their statements relayed by BleepingComputer , this action is not motivated by extortion but by a desire to « protect the group’s image ».
ShinyHunters’ attacks are not limited to the public sector: Mandiant has notified over 100 organizations worldwide, primarily in the United States, including entities in the education, healthcare, and government sectors. The group specifically targets Oracle PeopleSoft environments, widely used for human resources and financial management.
What this changes here
In Benin and West Africa, where administrations and businesses extensively use Oracle solutions for human resources, financial, or logistics management, this ShinyHunters campaign underscores the urgency of updating security patches, particularly for products like PeopleSoft. Organizations could see their systems exposed to similar attacks if Web Application Firewall (WAF) rules are not regularly audited to detect URL encoding bypasses. Furthermore, the use of backdoors such as SIDEEYE and lateral movement techniques via Neo-reGeorg highlights the need to actively monitor abnormal behaviors within networks, especially in sensitive sectors like healthcare or education, where critical data is often centralized.
The alleged breach at the FBI, though not officially confirmed, also highlights the risks tied to reliance on Oracle solutions in governmental infrastructures. Beninese and West African administrations may, in the long term, face similar demands from cybercriminal groups, hence the importance of documenting and encrypting sensitive data to limit the impact in case of a breach.
Sources