Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240) — Threadlinqs Intelligence
As of 2026-07-22, Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240) is a critical-severity vulnerability threat attributed to UNC6240, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1094 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-22 · revalidated 1× · latest source
Attribution: UNC6240 · FINANCIAL
CVE-2026-35273 (CVSS 9.8) is a pre-authentication remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.61/8.62, in which the unauthenticated /PSEMHUB/hub endpoint
CVE-2026-35273 affects the Updates Environment Management (EMHub/PSEMHUB) component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 (earlier unsupported versions are likely also affected). The PeopleSoft web tier co-hosts the Integration Broker gateway (/PSIGW/HttpListeningConnector) and the Environment Management Hub (/PSEMHUB/hub) without requiring authentication on either. An attacker posts a crafted XML envelope (a DOCTYPE external-entity reference, an EnvironmentManagement message, or an IBRequest SOAP message) whose sourceURL/url/HubURL element points at an attacker-controlled or loopback (127.0.0.1) target. Because the Integration Broker does not validate that submitted XML documents avoid referencing internal or external network resources, it acts as an unauthenticated SSRF proxy, relaying the request to the local Hub. The Hub's /PSEMHUB/hub handler then treats the value of the OPERATION POST parameter as a serialized Java object and deserializes it via XMLDecoder before any authentication check occurs, allowing arbitrary Java object instantiation from classes already present on the PeopleSoft classpath (a gadget chain of legacy XML-deserialization primitives combined with a zero-day logic flaw that bypasses input validation). Published exploitation invokes Hub operations such as FILECHUNKING, REGISTER_WITHOUT_PEERNAME, and HANDLE_MESSAGE to achieve remote code execution inside the PSEMHUB WebLogic JVM process, running as the PeopleSoft application-server OS user (commonly 'psoft').
Google Mandiant assessed that UNC6240 (publicly self-identifying as ShinyHunters, and increasingly operating under the federated 'Scattered Lapsus$ Hunters' brand alongside Scattered Spider and LAPSUS$-linked actors) exploited CVE-2026-35273 as a zero-day for approximately two weeks -- May 27 to June 9, 2026 -- before Oracle's advisory. At 22:14 UTC on May 27, 2026 the actor stood up a customized MeshCentral (v1.1.59) open-source remote monitoring and management server on staging infrastructure to serve as a command-and-control hub; eleven minutes later (22:25 UTC) they installed the 'acme-client' npm package to automatically provision Let's Encrypt TLS certificates for a masquerade domain, azurenetfiles.net, styled to resemble Microsoft's legitimate Azure NetApp Files service. Compiled Windows MeshCentral agent binaries (meshagent32-azure-ops.exe / meshagent64-azure-ops.exe) were staged to call back to wss://azurenetfiles.net:443/agent.ashx. Five sequential staging IPs (142.11.200.186-190) ran exposed Python SimpleHTTPServer instances on TCP/8888, publicly listing attacker tooling and shell/command history.
Post-exploitation activity included harvesting database and application credentials from the psappsrv.cfg PeopleSoft application-server configuration file, then using the uon_fanout.sh shell script to spray those credentials (targeting the psoft, oracle, and linuxadm accounts, with SSH-key fallback if password auth failed) against internal hosts enumerated from /etc/hosts, enabling lateral movement across PeopleSoft server tiers. Collected data was compressed with zstd prior to exfiltration over an outbound SSH connection to infrastructure hosting a public mirror of the ShinyHunters Tor leak site (176.120.22.24). Compromised hosts were defaced with a marker file, README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, dropped into WebLogic and Process Scheduler directories, alongside recently modified XML files consistent with XMLDecoder-based persistence.
UNC6240/ShinyHunters ran a 'pay-or-leak' extortion model -- no ransomware encryption was deployed; victims retained system access throughout, with leverage instead coming from the threat of publishing stolen data. Mandiant notified more than 100 organizations whose internet-facing systems matched vulnerable PeopleSoft endpoints; 68% were higher-education institutions, predominantly in the United States. Confirmed named victims include the University of Nottingham (UK, with
Weaknesses (CWE)
CWE-306, CWE-918, CWE-502
Target sectors: education, higher education, automotive, international-organizations, government administration
Target regions: North America, Europe, Asia-Pacific, united kingdom
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-35273, CVE-2026-35278, CVE-2026-35271, T1595, T1583, T1588, T1608, T1190, T1059, T1505, T1068, T1036, T1552