ProBackend
erp vulnerabilities zero day exploits
1 hour ago5 min read

When ERP Software Security Ignores the Percent Sign: ShinyHunters' WAF Bypass Against PeopleSoft

ShinyHunters encoded a single letter in their exploit URL to sidestep WAF rules protecting Oracle PeopleSoft CVE-2026-35273, resuming a global data-theft campaign that already hit the FBI's own infrastructure.

A Single Percent Sign Broke the Fix

Here's the uncomfortable truth about patching actively exploited vulnerabilities: applying the fix and deploying a web application firewall mitigation are not the same as actually being safe. ShinyHunters just proved that again, using a URL-encoding trick so elementary it should have been in every WAF rule from day one.

On September 22, 2026, Google-owned Mandiant documented the extortion gang encoding the letter "P" in /PSEMLHB/ as %50, producing requests to /%50SEMHUB/. They also threw uppercase and lowercase permutations into the mix — PEOPLESOFT, PeopleSoft — anything to slip past rules that were case-sensitive and literal about their path matching.

The vulnerability they're encoding around is CVE-2026-35273, the unauthenticated RCE in Oracle PeopleSoft's integration broker that grants high-privilege access without credentials. It was listed in CISA's KEV catalog within days of public proof-of-concept code appearing. For organizations that couldn't patch immediately, WAF signatures were the interim shield. That shield just evaporated.

The Two-Stage Probe: Quiet Recon, Loud Payload

The technique is methodical in a way that should worry anyone who assumed WAF logs would catch this in bulk. Mandiant describes a two-phase approach.

Phase one: a single POST request carrying a serialized Java object, aimed at the encoded endpoint like /%50SEMHUB/. No payload. No shell. Just a question — "is this thing alive?" The response tells the attacker whether the backend integration broker is reachable despite whatever WAF sits in front of it.

Phase two: if that probe returns the right signal, the attacker comes back with a crafted exploit designed to drop a JSP web shell. Mandiant observed three filenames — x.jsp, u.jsp, and u2.jsp, all of which are simple file-access checks you can run against your own web server today.

This isn't a novel technique in the academic sense. URL encoding has been a WAF evasion staple since the early 2000s. What makes it consequential here is the target: PeopleSoft runs payroll, HR, and benefits for some of the largest enterprises and government agencies on Earth. The blast radius of a WAF bypass in this ecosystem is measured in millions of employee records, not a single application's session tokens.

The Backdoor Stack: SIDEEYE, Neo-reGeorg, MeshAgent

Once a web shell lands, the real work begins. Mandiant observed ShinyHunters deploying a backdoor they track as SIDEEYE via a dropper called P1e64.exe. The backdoor isn't just a foothold, it provides what Mandiant characterizes as "comprehensive access to data stores, file repositories, databases, and the application environment."

That's not an exaggeration. The integration broker sits at a privileged intersection of the PeopleSoft architecture. From there, the attacker isn't crawling through the application UI like a normal user. They're at the plumbing level.

For command-and-control and lateral reach, the group layered on two more tools:

  • Neo-reGeorg, a tunneling toolkit that routes malicious traffic through the compromised web server, making outbound C2 look like legitimate HTTP on port 80 or 443.
  • MeshAgent, a legitimate remote administration tool that ShinyHunters abuses to maintain persistent access even after a web shell gets deleted during incident response.

The combination is deliberate. Delete the JSP file, and you still have a remote-access agent installed as a service. Close the tunnel, and the attacker reconnects through it hours later.

FBI Jobs and the Global Body Count

This wasn't theoretical for long. On September 3, 2026, weeks before Mandiant's discovery, ShinyHunters posted on BreachForums confirming they'd used this exact technique against the FBI Jobs portal, a PeopleSoft-powered instance hosting job listings and applicant data. The FBI never publicly confirmed the breach.

Mandiant, which tracks the group under the name UNC6395, has catalogued victims in at least 11 countries across government, healthcare, education, hospitality, and technology sectors. The majority remain in the US, with Canada, India, Italy, Japan, the Netherlands, Poland, Romania, Spain, and the UK also reporting compromises. The full scope of that global enterprise data extortion wave makes the encoded-endpoint trick even more consequential.

If you're tracking the broader context of ShinyHunters' exploitation of this same CVE against Ernst & Young and university systems, this WAF bypass represents the latest iteration of a campaign that has been running since June 2026 without any sign of the operators slowing down.

Detection: What You Can Actually Do Right Now

Mandiant's remediation guidance is refreshingly specific. If you run PeopleSoft, or you're responsible for ERP software security across a mixed enterprise estate, here's the checklist:

Audit WebLogic access logs for these patterns:

  • /%50SEMHUB/ and any other percent-encoded variant of the integration broker endpoint
  • Uppercase or mixed-case permutations like PEOPLESOFT and PeopleSoft in URI paths
  • File-access requests to /x.jsp, /u.jsp, or /u2.jsp

Check for artifacts:

  • SIDEEYE backdoor binaries
  • Neo-reGeorg files on disk
  • MeshAgent installed outside your sanctioned remote-access inventory

Mandiant published a YARA rule on GitHub to help hunt for these artifacts across large estates.

Apply the patch. Oracle's July 21, 2026 security update contains the fix for CVE-2026-35273. This is the only permanent answer. WAF rules are a bandage that shifts with each new encoding trick the adversary invents.

The Broader Lesson for ERP Software Security

The encoding trick itself is trivial. A single %50 where a P should be. The reason it matters isn't sophistication, it's the gap between "mitigation deployed" and "mitigation working." Security teams that checked their WAF dashboard, saw zero blocked requests against /PSHEUB/, and called it a win had no visibility into traffic that technically looked different at the string level but executed the same way server-side.

This is the pattern that CISA's KEV catalog exists to break, forcing the conversation away from interim workarounds and toward "have you actually patched this?" The answer should always be the patch. Everything else is buying time against an adversary who just proved they can buy more of it than you think.

The ShinyHunters campaign against PeopleSoft shows no indication of stopping. Mandiant's assessment puts most confirmed victims in the US, with the group's reach spanning four continents and sectors from healthcare to defense-adjacent government. Organizations running unpatched PeopleSoft instances are still exposed. The WAF didn't save them. The patch will, if they actually deploy it.

a single percent sign broke the fix

More blogs