Skip to content
vulnerabilitySupply Chaincredential-theft

ShinyHunters Breached Oracle PeopleSoft Through WAF Bypass

2 min read
Share

What happened

The threat group ShinyHunters (tracked by Mandiant as UNC6240) breached a large North American university's Oracle PeopleSoft human resources and student information system. Attackers used percent-encoded URL sequences to bypass the institution's web application firewall, ultimately exfiltrating data on approximately 6 million students and staff members. The stolen dataset included usernames, hashed passwords, email addresses, and partial Social Security Numbers.

The bypass technique

Oracle PeopleSoft exposes a rich set of web endpoints for HR, payroll, and student services. Many organizations front these with a WAF configured to block common injection strings. ShinyHunters encoded their payloads using double percent-encoding: for example, turning a single quote from %27 to %2527. A WAF that decodes input only once will see %2527 as a literal string and allow it through; the backend application then decodes it a second time, resolving it to the intended injection character. This class of bypass is not new, but PeopleSoft deployments remain systemically under-tested against multi-pass decoding attacks.

Recommended actions

Review your WAF configuration to confirm it performs recursive URL decoding before inspecting payloads. A WAF that decodes only once is vulnerable to double-encoding bypasses. Apply Oracle's most recent PeopleSoft security bundles and enable PeopleSoft's built-in activity monitoring to flag anomalous query volumes on sensitive fields. Rotate any credentials exposed in this event and enforce multi-factor authentication on all PeopleSoft administrator and self-service accounts.

The bottom line

Percent-encoding bypasses have been in the attacker playbook for two decades. The fact that they still succeed against production enterprise systems in 2026 points to a gap between WAF purchasing and WAF configuration. A WAF that ships with default rules is a starting point, not a finished control. Organizations running PeopleSoft should add WAF bypass testing to their annual application security review schedule.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need a second opinion on your enterprise application layer defenses.

Related articles