Security1 publisher3 min readPublished
One URL-encoded letter gets ShinyHunters past PeopleSoft WAF rules on unpatched servers
ShinyHunters is again exploiting Oracle PeopleSoft flaw CVE-2026-35273, getting past WAF rules by URL-encoding one letter of the path, Mandiant reported. The servers now in reach are the ones whose operators filtered the endpoint and never applied Oracle's patch.
The Watch · Security desk

What happened
- The FBI's portals for job applicants and special agent applicants remain offline after what appear to be successful compromises by ShinyHunters.
- The FBI confirmed last week that it was investigating the group's claim to have taken personal information on FBI employees.
- ShinyHunters told The Register it breached the portals through an Oracle PeopleSoft zero-day that is still unspecified and unconfirmed.
- The group first exploited CVE-2026-35273 as a zero-day in May and June 2026, mostly against academic institutions.
- Mandiant says the group's targeting now also covers technology, IT services, healthcare, agriculture, transportation and government.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure PeopleSoft servers that answered the May-June wave with a string-matching WAF rule and no patch can be reached again through the same Environment Management Hub endpoint.
- decision Operators who counted a WAF rule as their CVE-2026-35273 mitigation are back to Oracle's two options: apply the patch or take PeopleSoft servers off external networks.
- contradiction The FBI claim names an unconfirmed zero-day while the documented campaign uses a patched CVE, so a fully patched PeopleSoft site cannot yet rule itself out.
- precedent The group rewrote its exploit around published mitigation advice, so the next filter-only workaround for PeopleSoft can expect the same treatment.
%50 is the URL-encoded form of the letter P. A WAF rule that matches the literal string /PSEMHUB/ does not match /%50SEMHUB/, and the request still reaches the Environment Management Hub endpoint [11]. Mandiant's analysts wrote that the change "allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure" [11]. They had warned about this during the first wave. "Relying solely on Web Application Firewall (WAF) body-inspection rules is insufficient, as these controls can be bypassed," Mandiant noted then [9].
The bypass only matters for sites that stopped at a filter. At the time, Oracle's advice was to apply the emergency patch. Sites that could not patch were told to restrict PeopleSoft application and web servers to trusted internal networks and to block external access to the vulnerable endpoints at the perimeter [8]. Mandiant wrote that the group "adapted to published defensive guidance, targeting organizations that implemented WAF rules but did not patch the vulnerability" [12]. Patched servers are outside the target set Mandiant describes [12].
On the FBI side, the outage and the investigation are on the record [1][2]. The rest comes from the group. ShinyHunters says it also reached FBI-managed servers on AWS GovCloud and took personnel files on current, former and prospective employees [4]. It claims personal data on tens of thousands of agents and applicants, plus the agents' medical data [5]. According to the BBC, the group claims access to FBIJobs, the BEAST background-check system, the MedLink medical-records system and the BICS investigative platform [14]. Reuters matched the career details of eight people in the leak to court filings, news articles and public profiles. It could not verify that all the job assignments were authentic or current [15].
Help Net Security's report does not tie the FBI intrusion to CVE-2026-35273 or to the tools Mandiant documented. If the group's zero-day is a separate bug, Oracle's CVE-2026-35273 patch would not cover it [3].
The group says it is not after money. It says the attack answers a recent public service announcement that advised victims not to pay the ransom, and it has threatened to publish the files unless the FBI retracts what it calls "false allegations" [6].
A PeopleSoft hunt does not have to wait for Oracle to confirm a new flaw. Mandiant documented what the group does once inside: it deploys web shells, installs the MeshAgent remote management tool and runs commands filelessly [13]. MeshAgent is legitimate software [13]. On a PeopleSoft web server, the thing to look for is an install that nobody in IT can explain. The entry signature Mandiant published is a request for /%50SEMHUB/ in place of /PSEMHUB/ [11].
What to watch
- Oracle confirming or denying a PeopleSoft flaw beyond CVE-2026-35273, with an advisory or patch that would settle the zero-day claim.
- Mandiant or the FBI tying the FBI portal intrusion to CVE-2026-35273 or to the web shell and MeshAgent activity documented in the campaign.
- Another encoded variant of the PSEMHUB path, if the group adapts again to rules written against /%50SEMHUB/.