# Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240)

> CVE-2026-35273 (CVSS 9.8) is a pre-authentication remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.61/8.62, in which the unauthenticated /PSEMHUB/hub endpoint deserializes attacker-controlled Java objects via XMLDecoder, reachable through an SSRF chain in the /PSIGW/HttpListeningConnector Integration Broker gateway. The financially motivated extortion group UNC6240 (ShinyHunters) exploited it as a zero-day from May 27 to June 9, 2026, compromising 300+ PeopleSoft instances at 100+ organizations (68% higher education) before Oracle's June 10, 2026 out-of-band patch and the June 12, 2026 CISA KEV addition.

- **Published:** 2026-07-03T00:00:00Z
- **Last reviewed:** 2026-09-27T03:03:46.595Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1094
- **ID:** TL-2026-1094
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** UNC6240
- **Detections:** 9 · **IOCs:** 45 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-35273, CVE-2026-35278, CVE-2026-35271

## Description

CVE-2026-35273 affects the Updates Environment Management (EMHub/PSEMHUB) component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 (earlier unsupported versions are likely also affected). The PeopleSoft web tier co-hosts the Integration Broker gateway (/PSIGW/HttpListeningConnector) and the Environment Management Hub (/PSEMHUB/hub) without requiring authentication on either. An attacker posts a crafted XML envelope (a DOCTYPE external-entity reference, an EnvironmentManagement message, or an IBRequest SOAP message) whose sourceURL/url/HubURL element points at an attacker-controlled or loopback (127.0.0.1) target. Because the Integration Broker does not validate that submitted XML documents avoid referencing internal or external network resources, it acts as an unauthenticated SSRF proxy, relaying the request to the local Hub. The Hub's /PSEMHUB/hub handler then treats the value of the OPERATION POST parameter as a serialized Java object and deserializes it via XMLDecoder before any authentication check occurs, allowing arbitrary Java object instantiation from classes already present on the PeopleSoft classpath (a gadget chain of legacy XML-deserialization primitives combined with a zero-day logic flaw that bypasses input validation). Published exploitation invokes Hub operations such as FILECHUNKING, REGISTER_WITHOUT_PEERNAME, and HANDLE_MESSAGE to achieve remote code execution inside the PSEMHUB WebLogic JVM process, running as the PeopleSoft application-server OS user (commonly 'psoft').

Google Mandiant assessed that UNC6240 (publicly self-identifying as ShinyHunters, and increasingly operating under the federated 'Scattered Lapsus$ Hunters' brand alongside Scattered Spider and LAPSUS$-linked actors) exploited CVE-2026-35273 as a zero-day for approximately two weeks -- May 27 to June 9, 2026 -- before Oracle's advisory. At 22:14 UTC on May 27, 2026 the actor stood up a customized MeshCentral (v1.1.59) open-source remote monitoring and management server on staging infrastructure to serve as a command-and-control hub; eleven minutes later (22:25 UTC) they installed the 'acme-client' npm package to automatically provision Let's Encrypt TLS certificates for a masquerade domain, azurenetfiles.net, styled to resemble Microsoft's legitimate Azure NetApp Files service. Compiled Windows MeshCentral agent binaries (meshagent32-azure-ops.exe / meshagent64-azure-ops.exe) were staged to call back to wss://azurenetfiles.net:443/agent.ashx. Five sequential staging IPs (142.11.200.186-190) ran exposed Python SimpleHTTPServer instances on TCP/8888, publicly listing attacker tooling and shell/command history.

Post-exploitation activity included harvesting database and application credentials from the psappsrv.cfg PeopleSoft application-server configuration file, then using the uon_fanout.sh shell script to spray those credentials (targeting the psoft, oracle, and linuxadm accounts, with SSH-key fallback if password auth failed) against internal hosts enumerated from /etc/hosts, enabling lateral movement across PeopleSoft server tiers. Collected data was compressed with zstd prior to exfiltration over an outbound SSH connection to infrastructure hosting a public mirror of the ShinyHunters Tor leak site (176.120.22.24). Compromised hosts were defaced with a marker file, README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, dropped into WebLogic and Process Scheduler directories, alongside recently modified XML files consistent with XMLDecoder-based persistence.

UNC6240/ShinyHunters ran a 'pay-or-leak' extortion model -- no ransomware encryption was deployed; victims retained system access throughout, with leverage instead coming from the threat of publishing stolen data. Mandiant notified more than 100 organizations whose internet-facing systems matched vulnerable PeopleSoft endpoints; 68% were higher-education institutions, predominantly in the United States. Confirmed named victims include the University of Nottingham (UK, with campuses in Malaysia and China), from which roughly 40GB covering an estimated 454,600-500,000 current and former student records was published on June 9, 2026 after the university declined to pay; the Council of Europe, whose data was claimed on June 14, 2026 with a June 16 ransom deadline, resulting in publication of a 297GB claimed dataset (payroll records for 10,000+ employees from 2011-2026, 14,000+ CVs, HR/Secretariat/Parliamentary Assembly files); and Nissan Americas, which filed breach notifications on June 25, 2026 (publicly reported June 29, 2026) after employee PII -- SSNs, Social Insurance Numbers, National Identification Numbers, banking details, and tax/financial records for staff in the US, Canada, Mexico, and Brazil -- was exposed.

Oracle published a security alert and out-of-band emergency patch for CVE-2026-35273 on June 10, 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 12, 2026, with a federal remediation deadline of July 3, 2026. Trend Micro's Zero Day Initiative/Trend Research and multiple vendors (Rapid7, Qualys, Arctic Wolf, SOCRadar) published independent technical and detection guidance in the following weeks.

## MITRE ATT&CK

- T1595 Active Scanning
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1608 Stage Capabilities
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1068 Exploitation for Privilege Escalation
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1018 Remote System Discovery
- T1087 Account Discovery
- T1021 Remote Services
- T1560 Archive Collected Data
- T1219 Remote Access Tools
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1048 Exfiltration Over Alternative Protocol
- T1491 Defacement
- T1657 Financial Theft
- T1187 Forced Authentication
- T1570 Lateral Tool Transfer
- T1595.002 Active Scanning: Vulnerability Scanning
- T1596.003 Search Open Technical Databases: Digital Certificates
- T1596.005 Search Open Technical Databases: Scan Databases
- T1588.002 Obtain Capabilities: Tool
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1505.003 Server Software Component: Web Shell
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1552.001 Unsecured Credentials: Credentials In Files
- T1090 Proxy
- T1105 Ingress Tool Transfer

## Sources

- [CVE-2026-35273: Oracle PeopleSoft RCE Zero-Day Explained](https://www.picussecurity.com/resource/blog/cve-2026-35273-oracle-peoplesoft-rce-zero-day-explained)
- [Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/)
- [Oracle Security Alert Advisory - CVE-2026-35273](https://www.oracle.com/security-alerts/alert-cve-2026-35273.html)
- [CVE-2026-35273 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-35273)
- [CISA Adds One Known Exploited Vulnerability to Catalog](https://www.cisa.gov/news-events/alerts/2026/06/12/cisa-adds-one-known-exploited-vulnerability-catalog)
- [ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit](https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit)
- [PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM](https://www.trendmicro.com/en_us/research/26/f/PeopleTools.html)
- [CVE-2026-35273 - Defending Against the Oracle PeopleSoft PSEMHUB Authentication Bypass](https://threatprotect.qualys.com/2026/06/18/cve-2026-35273-defending-against-the-oracle-peoplesoft-psemhub-authentication-bypass/)
- [ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities](https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html)
- [Oracle PeopleSoft zero-day fuels ShinyHunters extortion spree](https://www.csoonline.com/article/4184408/oracle-peoplesoft-zero%E2%80%91day-fuels-shinyhunters-extortion-spree.html)
- [Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert](https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/)
- [Nissan discloses employee data breach linked to Oracle zero-day attacks](https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/)
- [Council of Europe Data Breach: ShinyHunters Makes 10,000 Employees' Records Permanent](https://www.techtimes.com/articles/318714/20260621/council-europe-data-breach-shinyhunters-makes-10000-employees-records-permanent.htm)
- [Council of Europe hacked in ShinyHunters' PeopleSoft heist](https://www.theregister.com/cyber-crime/2026/06/15/council-of-europe-hacked-in-shinyhunters-peoplesoft-heist/5255757)
- [ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day](https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-claims-oracle-peoplesoft-0-day-hit-100-orgs/5254443)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1094
