Skip to finding
§
High
Edge — RCE
Confirmed
CVE-2026-35273

One encoded path byte bypasses PeopleSoft’s literal WAF rule, and attackers are deploying web shells again.

The route reaches unpatched PSEMHUB deployments that operators protected only with a literal-path WAF or reverse-proxy rule.

Affects

Oracle PeopleSoft Enterprise PeopleTools, enterprise application servers commonly deployed on Windows or Linux with a WebLogic web tier.

What it enables

Unauthenticated command execution and persistent web-shell deployment through PeopleSoft installations operators believed were protected by path-based WAF rules

Attacker sends a serialized Java object to /%50SEMHUB/hub→↓A literal-path WAF or reverse proxy misses the encoded form→↓WebLogic decodes the path and routes it to the vulnerable PSEMHUB servlet→↓Deserialization executes commands as the PeopleSoft or WebLogic service account→↓Observed attackers deploy JSP web shells, fileless commands, tunnels, and remote-management tooling
Why this matters

The change is not another description of the deserialization flaw; it is evidence that the perimeter mitigation fails during ongoing exploitation on dozens of systems.

Detail and 2 sources
Required access

Internet reachability to an unpatched PeopleSoft PSEMHUB servlet, including deployments guarded only by literal-path WAF or reverse-proxy rules

Affected versions

PeopleTools 8.61, PeopleTools 8.62

A request to /%50SEMHUB/hub is checked in encoded form at the perimeter, decoded by WebLogic, and routed to the vulnerable servlet. Deserialization then executes commands as the PeopleSoft or WebLogic service account.

Observed follow-on activity includes JSP web shells, fileless commands, tunnels, and remote-management tooling. Oracle has published fixes for supported affected versions.

Evidence
Oracle confirms unauthenticated remote code execution and affected supported versionsMandiant observed the encoded-path bypass, command execution, and web-shell deployment on dozens of systemsPublic exploit code was not established from the opened sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 27, 2026