A WAF rule is not a patch: the PeopleSoft bypass
Reporting in the week of 22 September 2026 described attackers bypassing the web application firewall rules meant to mitigate CVE-2026-35273, a critical unauthenticated remote code execution flaw in Oracle PeopleSoft, using percent-encoding to evade the filters. Web shells were deployed on dozens of systems. If your organisation has ever said "we have a WAF rule for that" and moved on, this one is worth reading.
What happened
CVE-2026-35273 is an unauthenticated remote code execution vulnerability in Oracle PeopleSoft carrying a CVSS score of 9.8. Cybernews and BleepingComputer report that a ShinyHunters-linked group exploited it as a zero-day from 27 May to 9 June 2026, with Oracle's advisory following on 10 June.
The more recent development is the evasion. According to The Hacker News and BleepingComputer, attackers used a URL percent-encoding trick to bypass the WAF rules organisations had deployed to mitigate the flaw, then installed JSP web shells, a trojanised installer loading the SIDEEYE backdoor, and the MeshAgent remote management tool for persistence. The same group has claimed a breach of the FBI using a PeopleSoft zero-day, allegedly taking two to three terabytes of data on employees and applicants — a claim reported by CyberInsider and Cybernews, and one that remains the attackers' assertion rather than an established fact.
- The flaw
- CVE-2026-35273, CVSS 9.8, unauthenticated RCE in Oracle PeopleSoft.
- The bypass
- Percent-encoding the request so WAF signatures no longer matched.
- What followed
- Web shells, a backdoor and a remote management tool — persistence, not a smash and grab.
Why mitigations fail in exactly this way
Virtual patching has a legitimate place. When a vendor fix is not yet available, or a change window is weeks away, a WAF rule buys time and that time is genuinely valuable.
The trouble is what happens next. A mitigation that works on Monday tends to get recorded as "resolved" in the risk register by Friday, and the underlying patch quietly stops being urgent. But a WAF rule is a pattern match against how an attack looked when the rule was written. Encoding, casing, padding, chunking and parameter pollution are all standard ways to change how an attack looks without changing what it does. Signature evasion is not an advanced technique; it is a first resort.
So the honest framing is: a mitigation reduces exposure for an unknown period, against a determined attacker, until someone works out the variation. That is a reason to deploy one. It is not a reason to close the ticket.
Three practical changes
- Give every compensating control an expiry date. When you accept a mitigation instead of a fix, record the date the real remediation is due and review it. A mitigation with no end date becomes permanent by accident.
- Track mitigated and patched separately. If your reporting collapses both into "remediated", your board is being told something untrue. A dashboard that cannot distinguish them cannot support a decision.
- Hunt after the bypass, not just after the disclosure. Where a mitigation is defeated, the window during which you believed you were protected is exactly the window worth investigating. Look for web shells, unexpected scheduled tasks and remote management agents such as MeshAgent, which are legitimate software and therefore rarely flagged.
The ERP dimension
PeopleSoft is worth a specific mention because of what it holds. HR and finance systems concentrate exactly the data that hurts most: national identifiers, salary, bank details, addresses, next of kin, health-related absence, disciplinary records. That is special category data in places, and under the GDPR the consequences of losing it are not measured only in downtime.
These systems also tend to be operated conservatively, patched on long cycles, and treated as back-office rather than internet-facing — even when a self-service portal has quietly made them exactly that. If you run an ERP or HR platform with any internet exposure, it deserves the patch cadence of a perimeter device, not the cadence of an internal database, and the evidence of that cadence is something an auditor will increasingly expect to see.
Find out whether your mitigations actually hold, from someone trying to get past them.
Explore penetration testingCommon questions
A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft with a CVSS score of 9.8. Reporting indicates it was exploited as a zero-day from late May 2026, with Oracle publishing its advisory on 10 June 2026.
Not reliably. Attackers bypassed those rules using percent-encoding, which changes how the request looks without changing what it does. Treat a WAF rule as temporary cover that buys time for patching, and record a date by which the actual fix will be applied.
Patch if you have not, then hunt across the period you believed you were protected. Look for JSP web shells, unexpected scheduled tasks, new accounts and legitimate remote management tools such as MeshAgent, which attackers use precisely because they rarely trigger alerts.
Sources
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells — The Hacker News, 25 September 2026
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks — BleepingComputer, 25 September 2026
- ShinyHunters targets PeopleSoft again with Oracle zero-day attacks — Cybernews, 24 September 2026