CVE-2026-35273: Oracle PeopleSoft Zero-Day — ShinyHunters UNC6240 Attack Chain & Remediation
How ShinyHunters weaponized an unauthenticated Oracle PeopleSoft zero-day to exfiltrate employee records across Fortune 500 firms.
CVE-2026-35273
Severity: CVSS 9.8
Status: ⚠️ Zero-Day Exploited by ShinyHunters / UNC6240
Target Component: Oracle PeopleSoft Enterprise HCM
This post is part of the Week of June 12, 2026 Security Roundup.
Vulnerability Overview
CVE-2026-35273 is a pre-authentication remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools, rated CVSS 9.8 Critical. No credentials, no user interaction, and no special network position are required—only HTTP access to the PeopleSoft web tier. Oracle issued an out-of-band advisory on June 10, 2026, but the vulnerability had been exploited as a zero-day since at least May 27, when Google's Mandiant first observed the ShinyHunters (UNC6240) campaign.
CVE: CVE-2026-35273
CVSS v3.1: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CWE: CWE-502 (Deserialization of Untrusted Data) / CWE-94 (Improper Control of Code Generation)
Affected product: Oracle PeopleSoft Enterprise PeopleTools (all supported releases prior to June 2026 CPU)
Oracle advisory: Out-of-band, June 10, 2026
Technical Analysis
PeopleSoft's web tier exposes multiple endpoints under the Jolt protocol gateway and via its HTTP servlet layer. CVE-2026-35273 involves a failure to safely deserialize attacker-controlled input in a component of the PeopleTools web layer. A crafted HTTP POST request to a specific endpoint causes the JVM to deserialize a malicious payload, resulting in arbitrary OS command execution as the PeopleSoft application service account (typically psadm2 or psapp on Linux deployments).
The attack requires no session, no authentication token, and no prior reconnaissance beyond identifying a reachable PeopleSoft instance. Internet-facing instances were enumerated by ShinyHunters via Shodan and similar tools, targeting port 443 with the standard PeopleSoft web tier path patterns.
Attack Chain Breakdown
- Reconnaissance: Attacker scans for internet-facing PeopleSoft web tiers using Shodan queries for PeopleSoft-specific response headers and path patterns (
/psp/,/psc/). - Exploitation: Single crafted HTTP POST to the vulnerable endpoint triggers unauthenticated deserialization RCE. No login required.
- Persistence: Attacker writes a shell script (
[victim]_fanout.sh) and marker file (README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT) to PeopleSoft content directories. - Lateral movement: Fanout script reads
/etc/hoststo enumerate adjacent hosts and sprays a hardcoded credential list over SSH, propagating to internal systems. - Exfiltration: Student and staff PII (names, addresses, phone numbers, passport numbers, ethnicity data, disability records) exfiltrated to attacker infrastructure.
- Extortion: ShinyHunters contacts victim organizations with proof of data theft and demands payment.
Indicators of Compromise (IOCs)
Files:
README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT (in PeopleSoft content dirs)
[victim]_fanout.sh (in /tmp or PeopleSoft home dirs)
Commands to check for IOCs:
find /opt/oracle/psft -name "README-IF-YOU-SEE-THIS*" 2>/dev/null
find /tmp -name "*_fanout.sh" 2>/dev/null
find /home -name "*_fanout.sh" 2>/dev/null
Outbound connections:
SSH connections from PeopleSoft hosts to internal RFC1918 ranges (unusual for app servers)
Unexpected outbound TCP on ports 22, 443 from PeopleSoft servers
Affected Scope
- 300+ internet-facing PeopleSoft instances were vulnerable
- 100+ organizations confirmed compromised
- 68% of victims in higher education (University of Nottingham confirmed publicly)
- ~455,000 unique email addresses in Have I Been Pwned dataset from leaked data
Remediation
# Step 1: Apply Oracle's June 2026 out-of-band patch
# Download from Oracle Support (My Oracle Support):
# Patch ID: Per Oracle's June 10, 2026 advisory
# Apply to all PeopleTools releases per the advisory matrix
# Step 2: Restrict network access as temporary mitigation
# If patching is delayed, block unauthenticated external access:
iptables -I INPUT -p tcp --dport 443 -m conntrack --ctstate NEW -m set ! --match-set APPROVED_RANGES src -j DROP
# Step 3: Scan for IOCs
find /opt/oracle/psft /home /tmp -name "README-IF-YOU-SEE-THIS*" -o -name "*_fanout.sh" 2>/dev/null
# Step 4: Review SSH authorized_keys on all systems accessible from PeopleSoft hosts
for host in $(cat /etc/hosts | awk '{print $1}' | grep -v '^#' | grep -v '^127' | grep -v '^::'); do
echo "Checking $host"; ssh -o StrictHostKeyChecking=no -o ConnectTimeout=3 $host cat /root/.ssh/authorized_keys 2>/dev/null
done
# Step 5: Rotate ALL credentials
# - Database passwords
# - Service account passwords
# - SSH keys
# - Any secrets accessible from PeopleSoft application context
For the full list of affected PeopleTools versions and patch IDs, see the Oracle Security Advisory (June 10, 2026).