Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

A Critical Flaw in Oracle PeopleSoft Exposes Organizations to Web Shells and Compromised Data

A recent wave of attacks has compromised multiple organizations, exploiting a previously unknown vulnerability in Oracle’s PeopleSoft application. The attackers managed to bypass web application firewalls (WAFs) and inject malicious code into the system, deploying web shells that grant them unrestricted access to sensitive data.

The affected organizations all have one thing in common: they rely on Oracle’s PeopleSoft for human capital management (HCM) and financial management software. These systems are used by thousands of companies worldwide, handling everything from employee records to financial transactions. The attackers seem to be targeting these applications specifically, suggesting a high degree of sophistication and planning.

The flaw itself involves a privilege escalation vulnerability in the PeopleSoft application’s Java code. When exploited, it allows an attacker to elevate their privileges and inject malicious JavaScript code into the system. This can happen even if a WAF is in place, as the attackers have been able to bypass these security measures through various means. Once inside, they deploy web shells that give them control over the application’s backend.

The attacks are particularly concerning because they expose sensitive data such as employee records and financial information. The attackers’ ability to move undetected within the system for an extended period is also a major concern. Oracle has confirmed the existence of the vulnerability and released patches to address it, but many organizations may not have applied these updates yet.

As this incident highlights, even well-protected systems can be vulnerable to attacks if they’re not properly maintained. Organizations using PeopleSoft should immediately review their application security posture and apply any available patches. This includes ensuring that WAFs are configured correctly and up-to-date, as well as performing regular security audits and penetration testing.

For readers who may not have Oracle’s PeopleSoft installed, this incident serves as a reminder of the importance of maintaining good cybersecurity hygiene. Regularly updating software and keeping systems patched is crucial in preventing attacks like these. It’s also essential to educate users on safe practices when handling sensitive data and ensure that applications are configured with security best practices in mind.

Ultimately, this incident underscores the ongoing cat-and-mouse game between attackers and defenders in the world of cybersecurity. As long as vulnerabilities exist, there will be those who seek to exploit them. Staying vigilant and proactive in addressing these threats is essential for protecting sensitive data and maintaining business continuity.


Source: The Hacker News — 2026-09-26