Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

ShinyHunters Bypass WAF Rules to Exploit Oracle PeopleSoft (CVE-2026-35273) and Deploy SIDEEYE Backdoor

Threat actors leveraged CVE-2026-35273 in Oracle PeopleSoft, using URL‑encoded payloads to evade web‑application firewalls, install web shells and propagate the SIDEEYE backdoor. The flaw underscores the need for verifiable WAF configuration and continuous control evidence for audit readiness.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 hackread.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
hackread.com

Critical WAF Bypass Exploit in Oracle PeopleSoft (CVE‑2026‑35273) Enables SIDEEYE Backdoor Deployment

What It Is – ShinyHunters leveraged CVE‑2026‑35273 in Oracle PeopleSoft, using URL‑encoding tricks to evade Web Application Firewall (WAF) signatures. The bypass allowed the group to upload web shells and install the SIDEEYE backdoor, which can be used for persistent access and lateral movement.

Exploitability – Public proof‑of‑concepts and active exploitation have been observed in the wild. The vulnerability scores high on CVSS (≥8.0) due to remote code execution potential and the ease of bypassing a primary network defense.

Affected Products – Oracle PeopleSoft (all supported versions that have not applied the vendor’s security patch for CVE‑2026‑35273).

Why It Matters for Trust & Control Assurance

  • Continuous validation of WAF rule sets is a core control objective; a single bypass demonstrates that static rule lists are insufficient without ongoing testing.
  • Evidence of WAF effectiveness (log correlation, test results) provides defensible audit artifacts that satisfy multiple frameworks simultaneously.
  • Demonstrable remediation (patching, rule hardening, monitoring) signals due‑diligence to regulators and enterprise buyers demanding a verifiable security posture.

Recommended Actions

  • Apply Oracle’s security patch for CVE‑2026‑35273 immediately.
  • Conduct encoded‑payload testing of your WAF to confirm rule coverage and adjust signatures as needed.
  • Enable comprehensive WAF logging and feed logs into a centralized SIEM for real‑time detection.
  • Document the testing, remediation, and monitoring results in a trusted evidence repository to streamline audit readiness.

Source: HackRead article

📰 Original Source
https://hackread.com/shinyhunters-bypass-waf-rules-oracle-peoplesoft-attacks/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →