Reuters reported the FBI removed an Accenture contractor after a missed Oracle PeopleSoft security patch let ShinyHunters steal personal details from thousands of FBI employees. The flaw at issue is CVE-2026-35273.
Google-owned Mandiant says the group also used URL encoding to disguise the request well enough that a web application firewall rule did not recognize the blocked PeopleSoft Environment Management Hub endpoint, yet the request still reached it. In plain terms, the patch was skipped and the perimeter control was written narrowly enough to be walked around.
For organizations that let a contractor or MSP run internet-facing PeopleSoft, the exposure sits in the maintenance chain as much as in the software. If a managed platform misses an issued patch, a WAF rule can still leave employee-data systems reachable through a differently written URL.