ShinyHunters Found a Simple Way Around PeopleSoft Defences

Matthew Leo · Published September 28, 2026 · Business & Policy

A technician inspects cables in an office network cabinet.

Organizations using Oracle PeopleSoft may be exposed even if they added a firewall rule to block the vulnerable PSEMHUB path. Google-owned Mandiant says ShinyHunters changed a single character in its requests to get past some of those rules, then placed web shells on dozens of systems worldwide.

The campaign targets CVE-2026-35273, a PeopleSoft vulnerability that Oracle addressed in a June security alert. In its September 25 investigation, Mandiant says the attackers requested an encoded version of the PSEMHUB path. Some web application firewalls checked for the ordinary spelling before decoding the address. The PeopleSoft server decoded it and accepted the request.

Why the firewall rule failed

The detail is small but consequential: a filter that looks only for a literal string can miss a path written in an equivalent encoded form. It is a reminder that a workaround deployed quickly during an emergency can become a false sense of safety if the underlying software remains vulnerable.

Mandiant says this round reached beyond the education sector that featured in earlier attacks. The systems where it observed web shells span higher education, technology, health care, agriculture, transportation and government. The report does not identify Canadian victims or establish that every exposed PeopleSoft installation was compromised.

The attackers reportedly tested systems before using them. On some hosts Mandiant saw probing requests without later evidence of a web shell. That difference matters for incident response: a matching request in a log is a reason to investigate, not proof that data was stolen.

What PeopleSoft operators should check

Oracle's security alert and Mandiant's response advice point to the same first step: apply the vendor patch. Mandiant also advises disabling the Environment Management Hub service where it is not needed, or removing its application in a single-server setup. A firewall block is not a substitute for either change.

Administrators should review PeopleSoft web and proxy logs for requests to PSEMHUB in ordinary or encoded forms, especially unusual POST requests and access to JSP files. They should inspect the PSEMHUB application directory for files that do not belong there, then review outbound connections and unexpected remote-management software. If a system shows signs of compromise, credentials accessible to the PeopleSoft service account need rotation, including database and cloud credentials. Preserve evidence before cleaning up so the scope can be established.

For Canadian universities, hospitals and public agencies using PeopleSoft, the immediate question for the team running it is whether the June patch was installed. If the answer is only that a web application firewall rule was added, this new report shows why the exposure needs another look. Independent coverage of the Mandiant findings describes the same encoded-path method; the full victim count and any Canadian impact remain unconfirmed.

Read on Mapletechie