Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Attackers Bypass WAFs With One Encoded CharacterIncident
4 min readFor Security Engineers

Attackers Bypass WAFs With One Encoded Character

What Happened

ShinyHunters, identified as UNC6240, exploited CVE-2026-35273 in Oracle PeopleSoft to deploy web shells and achieve remote code execution across multiple organizations worldwide. This vulnerability has a CVSS score of 9.8, categorizing it as critical.

The attack succeeded even with web application firewalls (WAFs) in place. UNC6240 bypassed WAF rules by URL-encoding a single character in the request path. Once inside, they deployed web shells, gaining persistent access and the ability to execute arbitrary commands. About 25% of their commands ran with root or NT Authority\SYSTEM privileges, giving them full control over compromised systems.

Google and Mandiant tracked the campaign and released mitigation guidance. These attacks highlight a fundamental weakness in how many organizations deploy and configure perimeter security controls.

Timeline

The exact timeline is still under investigation, but the pattern follows a familiar sequence:

  1. Initial reconnaissance identified unpatched PeopleSoft instances.
  2. Attackers crafted exploit payloads with URL-encoded characters to evade WAF signature matching.
  3. Successful exploitation allowed web shell deployment.
  4. Attackers escalated privileges to root or SYSTEM level.
  5. Lateral movement and data exfiltration followed.

The rapid progression from initial compromise to privileged access suggests these weren't opportunistic attacks. UNC6240 was prepared with tested bypass techniques and post-exploitation tools.

Which Controls Failed

WAF signature matching failed due to reliance on exact string matches. When UNC6240 URL-encoded a single character in the exploit path, the WAF's pattern matching engine didn't recognize the request as malicious. The decoded request reached the application server unchanged, where PeopleSoft processed it as a valid input.

Patch management failed because organizations hadn't applied Oracle's security update. Critical vulnerabilities with CVSS scores above 9.0 should trigger emergency patching procedures, but many teams treat enterprise application patches as routine maintenance instead of urgent security work.

Privilege management failed because the web application ran with excessive permissions. When attackers gained code execution through the web shell, they inherited those privileges. A quarter of their commands ran as root or SYSTEM, which should never be necessary for a web application's normal operation.

Detection capabilities failed to identify the initial exploitation attempts or the subsequent web shell activity. Organizations with proper application security monitoring should detect unusual request patterns, new files in web directories, and processes spawning from web server contexts.

What Standards Require

PCI DSS v4.0.1 Requirement 6.4.3 mandates that all security vulnerabilities are identified and addressed based on a defined risk ranking methodology. A CVSS 9.8 vulnerability in an internet-facing application clearly falls into the highest risk category, requiring immediate remediation.

OWASP ASVS v4.0.3 Section 5.1.3 requires validation of input at the server side, after any normalization or decoding occurs. WAFs that only inspect raw requests miss attacks that become malicious after URL decoding, HTML entity decoding, or other transformations.

NIST 800-53 Rev 5 Control SI-3 (Malicious Code Protection) requires organizations to employ malicious code protection mechanisms at system entry and exit points. A WAF that can be bypassed with basic encoding doesn't meet this control's intent. The control specifically states that protection mechanisms should detect both known and unknown threats.

ISO/IEC 27001:2022 Control 8.8 (Management of Technical Vulnerabilities) requires organizations to obtain timely information about technical vulnerabilities and evaluate exposure. It also requires taking appropriate measures to address the associated risk. Leaving a 9.8 CVSS vulnerability unpatched violates this control.

SOC 2 Type II CC6.1 (Logical and Physical Access Controls) requires that the entity implements logical access security measures to protect against threats from sources outside its system boundaries. A bypassable WAF fails this criterion because it doesn't effectively protect the system boundary.

Lessons and Action Items

Stop treating WAFs as security boundaries. They're visibility and filtering tools, not impenetrable walls. Your architecture should assume the WAF can be bypassed. Place input validation in the application itself, after all decoding and normalization happens. OWASP ASVS Section 5.1 provides specific guidance on where and how to validate input.

Normalize and decode before inspection. Configure your WAF to URL-decode, HTML-entity-decode, and Unicode-normalize all input before applying signature rules. Many WAFs support this but don't enable it by default. Check your rule processing order now.

Patch critical vulnerabilities within 24 hours. Don't wait for your monthly maintenance window when you see CVSS scores above 9.0 in internet-facing applications. Build an emergency patching process that includes testing but compresses the timeline. Document this as part of your vulnerability management policy to satisfy PCI DSS Requirement 6.4.3.

Drop privileges for web applications. Your PeopleSoft instance (or any web application) should run with the minimum permissions needed for its function. It never needs root or SYSTEM. Create dedicated service accounts with restricted permissions. This limits what attackers can do even if they achieve code execution.

Monitor for web shells. Watch for new files appearing in web directories, especially files with script extensions (.jsp, .aspx, .php) that weren't deployed through your change management process. Monitor for web server processes spawning unexpected child processes. These patterns indicate web shell activity and should trigger immediate investigation.

Test your WAF bypass resistance. Don't assume your WAF configuration blocks encoded attacks. Use tools like Burp Suite or OWASP ZAP to send URL-encoded, double-encoded, and Unicode-encoded versions of known attack patterns. If any get through, you have work to do.

Implement defense in depth. Layer your controls so that bypassing one doesn't mean complete compromise. Even if attackers get past your WAF, they should hit input validation, then privilege restrictions, then monitoring and detection. Each layer gives you another chance to stop or detect the attack.

The ShinyHunters campaign proves that basic encoding tricks still defeat expensive security tools when those tools aren't properly configured. Your WAF vendor's default settings probably aren't sufficient. Review your configuration this week, test it with encoded payloads, and fix what you find before someone else does.

Topics:Incident
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like