Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

A critical vulnerability in Oracle’s PeopleSoft software has been exploited by attackers, who are using it to bypass web application firewalls (WAFs) and deploy malicious web shells on compromised servers. This flaw affects organizations worldwide that use PeopleSoft for HR management, financials, and other business operations.

The vulnerability, which was discovered earlier this year, allows attackers to execute arbitrary code on vulnerable systems by exploiting a cross-domain privilege escalation issue. By manipulating the way data is shared between domains, malicious actors can gain elevated privileges and move laterally within a network. In some cases, they have used this access to deploy web shells, which grant them remote access and control over compromised servers.

Oracle PeopleSoft is widely used in the public sector, including government agencies, as well as in industries such as education, healthcare, and finance. The vulnerability’s impact extends beyond these sectors, however, as it can be exploited by attackers to gain access to sensitive data, disrupt business operations, or even hold systems for ransom.

Attackers have demonstrated an impressive level of sophistication in exploiting this flaw, leveraging it to bypass traditional security measures like WAFs. This is particularly concerning because many organizations rely on these defenses to protect against common web-based attacks. By evading WAFs, attackers can more easily launch targeted campaigns and evade detection.

The vulnerability’s impact extends beyond mere exploitation; it also exposes the broader issue of identity exposure in the digital age. When sensitive data is mishandled or exposed, it creates a pathway for attackers to execute active attack paths. This includes exploiting cross-domain privilege escalation issues like the one affecting Oracle PeopleSoft. Understanding these connections can help organizations better protect themselves against future threats.

Given this threat landscape, organizations using Oracle PeopleSoft must take immediate action to patch their systems and review their security posture. A comprehensive risk assessment should include evaluating WAFs, reviewing access controls, and implementing additional security measures to prevent lateral movement within the network. This includes enforcing strict access controls, monitoring user activity, and regularly updating software dependencies.


Source: The Hacker News — 2026-09-26