---
title: "PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM"
url: https://daily.dev/posts/peoplesoft-peopletools-pre-authentication-rce-a-psigw-ssrf-chain-that-executes-inside-the-jvm-f19sjr0eu
source_url: https://www.trendmicro.com/en_us/research/26/f/PeopleTools.html
type: article
source: "Trend Micro"
published: 2026-06-19T00:52:09.567Z
updated: 2026-06-19T00:52:33.370Z
tags: ["security", "java"]
reading_time: 12
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM

**[Trend Micro](https://daily.dev/sources/trendmicro)** · 12 min read · 0 upvotes · 0 comments

## Summary

A critical pre-authentication RCE chain (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft PeopleTools 8.61 and 8.62 exploits the PSIGW Integration Broker gateway via SSRF to reach the internal PSEMHUB management servlet, then achieves code execution through Java XMLDecoder deserialization on web-tier restart. The chain is notably stealthy: execution occurs inside the WebLogic JVM with no child process spawned and no outbound beacon, making conventional behavioral and network detection ineffective. Oracle issued an out-of-band patch on June 10, 2026, but exploitation was observed in the wild from May 27 by threat actor SHADOW-AETHER-015 (ShinyHunters) targeting over 100 organizations. Post-exploitation options include JSP web shell deployment and NetNTLM credential coercion via SMB. Defenders are advised to patch immediately, restrict PSIGW network exposure, monitor envmetadata/ filesystem paths, and treat web-tier restarts as security-relevant events.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.trendmicro.com/en_us/research/26/f/PeopleTools.html>

## Similar posts on daily.dev

- [Active Exploitation of Oracle PeopleSoft Zero-Day \(CVE-2026-35273\)](https://daily.dev/posts/active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273--tyz4demr3) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments
- [Oracle mitigates PeopleSoft zero-day exploited in data theft attacks](https://daily.dev/posts/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks-ts5qbro18) · BleepingComputer · 1 upvotes · 0 comments
- [PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data](https://daily.dev/posts/peoplesoft-0-day-affecting-hundreds-of-organizations-steals-gigabytes-of-data-rbusirs36) · Ars Technica · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#java](https://daily.dev/tags/java)

[View this post on daily.dev](https://daily.dev/posts/peoplesoft-peopletools-pre-authentication-rce-a-psigw-ssrf-chain-that-executes-inside-the-jvm-f19sjr0eu)
