INFOthreat·

ShinyHunters Exploits Oracle PeopleSoft via WAF Bypass

The ShinyHunters extortion group is actively exploiting Oracle PeopleSoft servers by leveraging a URL-encoding technique to bypass existing Web Application Firewall (WAF) rules designed to mitigate CVE-2026-35273. This bypass allows the group to continue widespread exploitation of the underlying vulnerability, posing a significant risk to unpatched and inadequately protected PeopleSoft instances.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

The ShinyHunters extortion gang is actively targeting Oracle PeopleSoft servers, utilizing a sophisticated URL-encoding trick to circumvent Web Application Firewall (WAF) protections. This technique allows them to bypass rules intended to block exploitation of CVE-2026-35273, enabling continued widespread attacks against vulnerable systems. Organizations running Oracle PeopleSoft are at risk of data exfiltration and extortion if their WAFs are not configured to detect these bypass methods.

Technical Analysis

  • Target: Oracle PeopleSoft applications.
  • Vulnerability: Exploitation of CVE-2026-35273. Specific details of the underlying flaw are not provided in the source, but it is described as an Oracle PeopleSoft vulnerability.
  • Attack Vector: Web-based requests to the PeopleSoft application.
  • WAF Bypass Method: Threat actors employ a URL-encoding trick. This involves encoding parts of the malicious payload or request in a way that WAFs fail to properly decode or inspect, allowing the exploit payload to reach the application layer.
  • Impact: Successful exploitation can lead to unauthorized access, data exfiltration, and subsequent extortion demands by the ShinyHunters group.

Detection

  • Web Server Logs: Monitor web server access logs (e.g., Apache, Nginx, IIS) for requests targeting PeopleSoft application paths.
  • URL Encoding Anomalies: Look for unusually high levels of URL encoding (%xx sequences) within cs-uri-stem, cs-uri-query, or request bodies, especially when combined with common exploit patterns.
  • WAF Alerts: Review WAF logs for blocked requests that might indicate attempted exploitation, and analyze patterns of requests that are not blocked but contain suspicious encoding.
  • Application Logs: Monitor Oracle PeopleSoft application logs for signs of unusual activity, unauthorized access, or unexpected commands being executed.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Web Server – Suspicious URL Encoding in Request

title: Web Server - Suspicious URL Encoding in Request
id: 6a3e5b1c-d7f8-4e9a-b0c1-2f3d4e5a6b7c
status: experimental
description: Detects web requests containing multiple or specific URL-encoded characters often used in WAF bypasses or obfuscated attacks against web applications like Oracle PeopleSoft.
logsource:
  category: webserver
detection:
  selection_encoded_chars:
    cs-uri-stem|contains:
      - '%252f' # Double encoded slash
      - '%2f'   # Encoded slash
      - '%5c'   # Encoded backslash
      - '%3c'   # Encoded less than
      - '%3e'   # Encoded greater than
      - '%22'   # Encoded double quote
      - '%27'   # Encoded single quote
      - '%7b'   # Encoded open brace
      - '%7d'   # Encoded close brace
      - '%20'   # Encoded space
      - '%u002f' # Unicode encoded slash
      - '%u005c' # Unicode encoded backslash
  condition: selection_encoded_chars
level: high

Mitigations

  1. Patch Oracle PeopleSoft: Apply all available security patches for Oracle PeopleSoft, specifically addressing CVE-2026-35273 and any related vulnerabilities.
  2. Enhance WAF Rules: Review and update WAF configurations to ensure robust decoding capabilities and comprehensive inspection of URL-encoded content. Implement rules that specifically look for double-encoding or other bypass techniques.
  3. Input Validation: Implement strict input validation at the application layer to sanitize and validate all user-supplied data, reducing the effectiveness of encoded payloads.
  4. Network Segmentation: Isolate PeopleSoft servers on a dedicated network segment with strict ingress/egress filtering to limit potential lateral movement in case of compromise.
  5. Regular Audits: Conduct regular security audits and penetration tests on PeopleSoft deployments to identify and remediate vulnerabilities and WAF bypasses.

References

  • https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

  • T1190 — Exploit Public-Facing Application
  • T1562.007 — Disable or Modify Cloud Firewall
🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,512 input / 1,216 output tokens ·
Reviewed and approved by a human analyst before publication
#uncategorized