PeopleSoft CVE-2026-35273: How to Hunt the WAF Bypass


PeopleSoft CVE-2026-35273 exposed a gap between what a WAF reads and what an application executes. A request for /%50SEMHUB/ could slip past a literal /PSEMHUB/ rule, then be decoded and routed by PeopleSoft.
That one encoded character captures the problem. The firewall compared the spelling of the path; the application server interpreted its meaning. Two systems saw different text, but PeopleSoft reached the same vulnerable servlet.
Oracle released an out-of-band Security Alert and patch guidance on June 10, 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog two days later. On September 25, Mandiant described renewed exploitation by UNC6240, tracked as ShinyHunters, using encoded paths to get around literal WAF rules.
If you run PeopleTools 8.61 or 8.62, confirm patching and internet exposure, search every spelling of PSEMHUB, and correlate any hits with host and network activity. Oracle notes that unsupported earlier versions were not tested and are also likely affected.
How CVE-2026-35273 bypasses a literal WAF rule
Oracle rates CVE-2026-35273 as CVSS 9.8. The flaw affects the Updates Environment Management component in supported PeopleTools 8.61 and 8.62 releases and can be exploited remotely over HTTP without credentials. CISA classifies it as missing authentication for a critical function. According to Mandiant, attackers abuse Java deserialization in the Environment Management Hub, or PSEMHUB, servlet.
In plain terms, a sensitive administrative function responds to a caller who has not proved their identity. Until the system is patched or the component is removed, the controls upstream of PeopleSoft may be the only barrier in the way.
In many environments, that barrier included a WAF rule looking for the literal string /PSEMHUB/. Mandiant reports that attackers changed one character and requested /%50SEMHUB/; %50 is the URL-encoded form of the letter P.
A WAF or reverse proxy may evaluate the raw path before decoding it, while the PeopleSoft application server decodes the request and routes it to PSEMHUB. That is why defenders should assume that percent-encoded, mixed-case, double-encoded, or otherwise non-normalized versions of the path may appear. Blocking needs to happen after normalization, and logging should preserve both the raw request and its decoded form.
What defenders may see after exploitation
Mandiant observed five to 15 quiet POST requests to /%50SEMHUB/hub per target. On an unpatched server, those requests can return details about the host operating system without writing a file or disrupting the service. Early activity can therefore look like harmless probing even after the vulnerable service has responded.
Where exploitation continued, Mandiant observed JSP web shells beneath PSEMHUB.war, fileless command execution with output returned in the HTTP response, a trojanized Ple64.exe that loaded the SIDEEYE backdoor, Neo-reGeorg tunneling files, and MeshAgent on Linux. About one quarter of the observed commands ran as root or NT AUTHORITY\SYSTEM.
In a load-balanced environment, evidence may exist on only one node. Checking the first server and stopping there can create false reassurance.
PeopleSoft exposure and business risk
The exposure does not end at the web tier. Mandiant advises teams to review database audit logs for bulk queries or exports involving HR, payroll, and student-record tables. The PeopleSoft tier may also expose database connection strings, Integration Broker credentials, cloud credentials, and other secrets available to the compromised service context.
Mandiant describes UNC6240 as a data-theft extortion cluster. Its September activity placed web shells on dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation, and government.
One widely reported case is the FBI jobs portal, but the intrusion path remains unconfirmed. In separate reporting, ShinyHunters told BleepingComputer that it used the encoded-path bypass against FBIJobs.gov while also claiming a second, unknown PSEMHUB flaw. The FBI has confirmed only that it is investigating alleged unauthorized activity; it has not confirmed the breach vector or the reported data-loss claims. Those details should not be treated as findings from Oracle or Mandiant.
How to mitigate CVE-2026-35273
Patching is the anchor for the response. Oracle provides installation guidance through its Patch Availability Document, and Mandiant is equally direct: WAF rules and path-based blocking are not substitutes for the patch.
Where the component is unnecessary, remove it from the attack surface. Mandiant, citing Oracle's guidance, recommends disabling the EMHub service in multi-server configurations and removing PSEMHUB in single-server configurations. If EMHub cannot be disabled, block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector. Restricting those administrative components from the public internet does not disrupt normal PeopleSoft Internet Architecture browser sessions.
At the edge, decode and normalize the request path before evaluating the rule. Enforce the block on that normalized value, but keep both the original and decoded paths in the logs. Otherwise, the transformation that explains the bypass disappears from the evidence.
If you find a web shell or another unexpected payload, treat the host as compromised. Preserve the evidence and rotate every credential reachable from the PeopleSoft tier, including database connection strings in psappsrv.cfg, Integration Broker credentials, and cloud credentials. Given the actor's history, prepare for the possibility of extortion contact.
How to hunt PSEMHUB exploitation
The following hunts approach the campaign from four angles: encoded requests at the proxy or WAF, process activity on the host, outbound network connections, and file writes beneath the web archive.
As a risk-based starting point, review retained telemetry back to at least May 27, 2026, when Mandiant first observed zero-day exploitation. After Oracle's June 10 alert, later activity was exploitation of a patched vulnerability, sometimes through gaps in compensating WAF controls. The table and field names below reflect common schemas, so test each query against a known event before trusting the result. A match is an investigative lead, not proof of compromise.
Microsoft Sentinel KQL: encoded PSEMHUB requests
let Lookback = 120d;
CommonSecurityLog
| where TimeGenerated > ago(Lookback)
| extend RawUrl = tostring(RequestURL)
| extend Decoded = url_decode(url_decode(RawUrl))
| where Decoded contains "psemhub" or Decoded contains "psigw/httplisteningconnector"
| extend PathForm = iff(RawUrl contains_cs "/PSEMHUB/" or RawUrl contains_cs "/PSIGW/HttpListeningConnector",
"literal", "encoded, mixed-case, or double-encoded")
| project TimeGenerated, DeviceVendor, DeviceProduct, DestinationHostName, SourceIP,
RequestMethod, RawUrl, Decoded, PathForm, DeviceAction
| order by TimeGenerated ascThis assumes the WAF or proxy writes to CommonSecurityLog and stores the full path in RequestURL. Confirm that assumption with a known request. Administrators may legitimately use the literal path, so PathForm helps separate normal-looking traffic from encoded or unusual spellings. No results may simply mean that paths were not logged or the relevant dates have aged out of retention.
CrowdStrike Falcon CQL: shells and tooling on the PeopleSoft host
#event_simpleName=ProcessRollup2
| in(field=ComputerName, values=["psweb01", "psweb02"]) // your PeopleSoft web and app hosts
| case {
ParentBaseFileName=/^java(\.exe)?$/i FileName=/^(cmd\.exe|sh|bash)$/i | Reason := "shell spawned by java";
CommandLine=/psappsrv\.cfg|PSEMHUB\.war/i | Reason := "PeopleSoft config or PSEMHUB path in a command line";
FileName=/^(Ple64\.exe|meshagent.*)$/i | Reason := "file name named in Mandiant reporting";
FileName=/^(sshpass|zstd|rsync)$/i | Reason := "staging tool named in Mandiant reporting";
* | Reason := "";
}
| Reason != ""
| table([@timestamp, ComputerName, UserSid, ParentBaseFileName, FileName, CommandLine, Reason], limit=1000)These are common Falcon endpoint fields; validate them against one known process event. Administrators, patch jobs, and backups can legitimately invoke shells, rsync, or psappsrv.cfg, so compare matches with approved change records. Fileless execution will not leave a JSP behind, but it may still appear as a shell launched beneath Java. An empty result may mean the sensor is missing or the host list is incomplete.
Splunk: outbound connections from PeopleSoft hosts
index=YOUR_NETWORK_INDEX
| eval src=coalesce(src_ip, src, source_ip), dest=coalesce(dest_ip, dest, destination_ip)
| eval dport=tonumber(coalesce(dest_port, dst_port, destination_port))
| search src IN ("10.20.30.11", "10.20.30.12") /* your PeopleSoft host addresses */
| where NOT (cidrmatch("10.0.0.0/8", dest) OR cidrmatch("172.16.0.0/12", dest) OR cidrmatch("192.168.0.0/16", dest))
| eval Reason=case(
match(dest, "^(5\.199\.162\.157|104\.219\.234\.138|162\.219\.30\.165)$"), "Mandiant September network indicator",
dport=3333 OR dport=3334, "SIDEEYE control and data ports from the report",
dport=445, "outbound SMB to an external address",
dport=873, "rsync to an external address",
true(), null())
| where isnotnull(Reason)
| stats earliest(_time) AS first latest(_time) AS last count BY src dest dport Reason
| sort 0 firstReplace the sample source addresses with your PeopleSoft hosts. Field names follow common Splunk CIM conventions but vary by firewall add-on, so confirm the mapping with a known connection. SIDEEYE used TCP/3333 for control and TCP/3334 for data with 162.219.30.165; do not assume every campaign connection uses those ports. Also review DNS or proxy telemetry for winmanage-me[.]network. These indicators are time-bound investigative leads, not proof by themselves.
Kibana: file writes beneath the PSEMHUB web archive
(file.path:(*PSEMHUB.war* or *psemhub.war*) and file.extension:(jsp or jspx or exe or xml))
or (process.parent.name:(java or java.exe) and process.name:(cmd.exe or sh or bash))
or process.command_line:(*psappsrv.cfg* or *sshpass* or *zstd*)This hunt uses Elastic Common Schema fields as they are commonly populated by endpoint products such as Elastic Defend. Confirm that those fields exist in the index you intend to search. Oracle patching and PeopleTools upgrades can legitimately write beneath the archive, so compare timestamps with change windows and look closely for the names Mandiant reported: x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe. If the query is empty, confirm that file telemetry exists and inspect the directory on every WebLogic node.
How to interpret the findings
Finding | Likely meaning | Next step |
Encoded or mixed-case PSEMHUB path from an external address | Attempted access that a literal WAF rule may have missed | Check the response code, host patch level, and follow-on activity |
Repeated POSTs to /%50SEMHUB/hub with no file or process change | Possible quiet verification or system enumeration | Patch or remove PSEMHUB and review every node |
Unexpected JSP or executable in PSEMHUB.war | Likely web shell or payload | Treat the host as compromised, preserve evidence, and rotate credentials |
Shell process beneath the WebLogic Java process | Possible fileless command execution | Compare with change records, then escalate |
Outbound traffic to Mandiant's listed indicators | Possible command-and-control or staging activity | Isolate the host and preserve network-flow evidence |
Empty results | Unknown—not proof that the environment is clean | Verify data sources, coverage, and retention before closing the investigation |
What this means for your team
A WAF denial can create a false sense of closure. It proves that one representation of a path was blocked; it does not prove that the application behind it was unreachable.
Patch the affected PeopleTools systems. Disable or remove the hub if it is not needed. Then search both raw and decoded access logs for every form of the path, across every node, going back to late May.
If you find activity, pivot quickly from the request to the identity behind the service. Determine what the PeopleSoft account could reach, which credentials were exposed, and whether the attacker moved beyond the web tier. That is the part of the response that is hardest to improvise under pressure.
How Inception can help
An investigation like this does not live in one console. It starts with an encoded request in proxy or WAF telemetry, moves into the WebLogic access log, and continues through process and network activity on the host. Inception Protection brings those signals into one managed detection and response investigation using the Microsoft Defender and Sentinel licenses you already have, so the request and the shell beneath Java are understood as one story—not two unrelated alerts.
If you want to test how well your Microsoft environment would surface activity like this, start with the free Inception Foresight M365 Assessment. If you are already seeing suspicious PSEMHUB activity, talk with Inception Security before the evidence ages out.
Sources and further reading



