Description
Oracle PeopleSoft environments are being targeted in a renewed exploitation campaign associated with UNC6240, a threat actor linked to the ShinyHunters ecosystem. The campaign abuses CVE-2026-35273, a critical vulnerability affecting the PeopleSoft Environment Management Hub (PSEMHUB), which can allow remote unauthenticated code execution.
Attackers have adapted their exploitation technique by using a URL-encoded representation of the PSEMHUB path. This can bypass certain WAF rules that rely on literal URL matching, allowing vulnerable systems to remain accessible despite perimeter protections.
Technical Description
CVE-2026-35273 affects Oracle PeopleSoft PeopleTools and the PeopleSoft Environment Management Hub. The vulnerability can be remotely exploited without authentication and may result in remote code execution.
The renewed campaign uses requests such as:
/%50SEMHUB/hub
The %50 value represents the letter P. After URL normalization, the application can interpret the request as:
/PSEMHUB/hub
This difference in URL processing can allow attackers to bypass security controls that inspect the request before normalization.
Attack Overview
The attack begins with POST requests targeting the encoded PSEMHUB path. Attackers can use these requests to determine whether a PeopleSoft server is vulnerable.
After successful exploitation, attackers have been observed deploying JSP web shells and executing commands directly through the vulnerable servlet. Additional tooling has been used for network tunneling, remote access and persistence.
Observed activity includes web shells such as x.jsp, u.jsp and u2.jsp, Neo-ReGeorg tunneling components, the SIDEEYE backdoor and MeshAgent on Linux systems.
Technical Analysis
The primary technique observed in the renewed campaign is URL encoding of the first character in the PSEMHUB path.
Instead of directly requesting:
/PSEMHUB/
attackers use:
/%50SEMHUB/
Security devices that perform literal string matching may fail to identify the encoded representation, while the downstream PeopleSoft application can decode the request and route it to the vulnerable servlet.
Attackers also sent multiple POST requests to /%50SEMHUB/hub containing serialized Java objects. Responses can provide information about the target environment and help attackers determine whether exploitation can proceed.
Following successful exploitation, attackers used JSP-based web shells for command execution and file uploads. Fileless command execution was also observed, meaning that malicious activity may occur without a web shell being written to disk.
On Windows systems, defenders may observe cmd.exe being launched by the WebLogic Java process. Linux systems may show /bin/sh or bash activity associated with the PeopleSoft/WebLogic process.
The campaign also involved the deployment of Ple64.exe, which masqueraded as a Light Alloy media player installer and was associated with the SIDEEYE backdoor. SIDEEYE supports capabilities including credential theft, process and file management, reverse shells and reverse-proxy functionality.
Neo-ReGeorg components such as tunnel.jsp and tunnel.jspx were also used for network tunneling. On Linux systems, attackers deployed MeshAgent, a legitimate remote-management component associated with MeshCentral.
Potential Impact
Successful exploitation may provide attackers with operating-system-level access to vulnerable PeopleSoft servers.
Potential consequences include:
Unauthorized access to PeopleSoft application data
Exposure of HR, payroll, financial and student information
Credential theft
Web-shell persistence
Remote command execution
Network tunneling
Lateral movement
Data collection and exfiltration
Potential extortion following data theft
The impact may be greater when PeopleSoft or WebLogic services operate with elevated privileges.
Recommendations & Immediate Actions
Apply the appropriate Oracle security update for CVE-2026-35273.
Disable or remove the Environment Management Hub where it is not required.
Review WAF and reverse-proxy rules for encoded versions of the PSEMHUB path.
Search WebLogic logs for
/PSEMHUB/,/%50SEMHUB/and POST requests to/hub.Inspect all WebLogic nodes for unexpected JSP, JSPX and executable files.
Search for
x.jsp,u.jsp,u2.jsp,tunnel.jsp,tunnel.jspxandPle64.exe.Investigate
cmd.exe,/bin/shorbashprocesses spawned by WebLogic.Rotate credentials accessible from compromised PeopleSoft systems.
Review database and network logs for evidence of data access or exfiltration.
Preventive Actions
Keep PeopleTools and PeopleSoft components fully patched.
Minimize public exposure of EMHub.
Restrict unnecessary external access to PeopleSoft administration and integration interfaces.
Normalize URLs before applying security rules where technically possible.
Monitor unexpected JSP and JSPX file creation.
Deploy endpoint monitoring on PeopleSoft and WebLogic servers.
Apply least privilege to PeopleSoft and WebLogic service accounts.
Avoid running WebLogic with root or SYSTEM privileges where possible.
Monitor outbound connections from application servers.
Maintain database auditing for sensitive records.
Conduct regular threat hunting for exploitation attempts and web shells.
Indicators of Compromise
IPv4:
5.199.162.157IPv4:
104.219.234.138IPv4:
162.219.30.165Domain:
winmanage-me.network
Conclusion
The renewed exploitation of CVE-2026-35273 demonstrates how attackers can adapt quickly when organizations introduce perimeter defenses without addressing the underlying vulnerability.
By encoding a single character in the PSEMHUB path, attackers can potentially bypass WAF rules based on literal URL matching and continue targeting vulnerable PeopleSoft environments.
Organizations should prioritize patching, reduce unnecessary exposure of EMHub, review historical WebLogic logs and inspect all application nodes for web shells, command execution and unauthorized remote-management tools. WAF protections and URL-based controls should be treated as additional defensive layers rather than replacements for vulnerability remediation.