Back to all lessons
Awareness Lessons
2 weeks ago

WAF Bypass Exposes Unpatched PeopleSoft Servers to ShinyHunters

ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft by using URL-encoding tricks to bypass WAF protections, reaching vulnerable endpoints that security teams believed were already shielded. This attack illustrates a critical and common misconception: WAFs are a compensating control, not a substitute for patching. Organizations that delayed applying the patch while relying solely on WAF rules created a false sense of security. Once the WAF was bypassed, attackers deployed web shells and exfiltrated data with minimal friction, demonstrating how a single unmitigated vulnerability can lead to full compromise.

Tactical Insight

Immediate actions

  • Apply Oracle's official patch for CVE-2026-35273 on all PeopleSoft instances immediately, regardless of WAF coverage.
  • Audit all internet-facing PeopleSoft servers for signs of web shell deployment or unauthorized executables.
  • Review and update WAF rule sets to detect URL-encoding and other obfuscation bypass techniques.

Long-term improvements

  • Establish a formal patch management policy with defined SLAs for critical CVEs on internet-facing systems (e.g., patch within 24–72 hours).
  • Never treat WAFs, IDS/IPS, or other perimeter controls as a permanent substitute for vulnerability remediation.
  • Implement network segmentation to isolate PeopleSoft and other ERP systems from the broader corporate network.

Detection measures

  • Deploy file integrity monitoring on PeopleSoft servers to detect unauthorized web shell creation or binary drops.
  • Enable detailed logging of all requests to sensitive endpoints (e.g., PSEMHUB) and alert on anomalous URL encoding patterns.
  • Conduct regular authenticated vulnerability scans and penetration tests against ERP systems to validate patch status and WAF effectiveness.