Grid Protection Alliance openPDC and openHistorian
Grid Protection Alliance openPDC and openHistorian affected by multiple critical vulnerabilities.
Summary
Multiple critical vulnerabilities have been discovered in Grid Protection Alliance's openPDC and openHistorian software, impacting versions prior to 2.9.482 for openPDC and 2.8.585 for openHistorian. These vulnerabilities, including deserialization of untrusted data, missing authentication, SSRF, and hard-coded credentials, could allow unauthenticated attackers to achieve remote code execution and gain administrative control. The vendor has released patches for some versions, but Docker images are not yet fixed.
Full text
ICS Advisory Grid Protection Alliance openPDC and openHistorian Release DateOctober 08, 2026 Alert CodeICSA-26-281-02 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: openPDC <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) openPDC (Docker image) <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278) openHistorian <2.8.580, <2.8.585 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) CVSS Vendor Equipment v3 9.8 Grid Protection Alliance openPDC 5 Vulnerabilities Deserialization of Untrusted Data, Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), Use of Hard-coded Credentials, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-100730 A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account. Read More 3 Affected Products Grid Protection Alliance openPDC <2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance has added additional validation into serialization logic in openPDC version 2.9.482 and later and openHistorian version 2.8.585 and later. Systems using Windows Authentication are additionally protected, as they require the attacker to already be authenticated to reach this function. Grid Protection Alliance openPDC (Docker image) <2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian <2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance has added additional validation into serialization logic in openPDC version 2.9.482 and later and openHistorian version 2.8.585 and later. Systems using Windows Authentication are additionally protected, as they require the attacker to already be authenticated to reach this function. Additional Metrics Relevant CWE: CWE-502 Deserialization of Untrusted Data CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N View CVE Details CVE-2026-105281 The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system. Read More 6 Affected Products Grid Protection Alliance openPDC <2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) <2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian <2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC <2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) <2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian <2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Additional Metrics Relevant CWE: CWE-306 Missing Authentication for Critical Function CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N View CVE Details CVE-2026-85479 The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it. Read More 9 Affected Products Grid Protection Alliance openPDC <2.9.482 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces. Grid Protection Alliance openPDC (Docker image) <2.9.482 Product Status: known_affected Remediations No fix plannedGrid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image. Grid Protection Alliance openHistorian <2.8.585 Product Status: known_affected Remediations Vendor fixGrid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explici
Indicators of Compromise
- cve — CVE-2026-104629
- cve — CVE-2026-100730
- cve — CVE-2026-105281
- cve — CVE-2026-85479
- cve — CVE-2026-101022
- cve — CVE-2026-105278