openPDC and openHistorian grid software: CISA ICSA-26-281-02 lists six flaws including a CVSS 9.8 deserialisation bug reachable without login when Windows Authentication is off and a 9.8 fixed admin password in the openPDC Docker image; fixed in openPDC 2.9.482 and openHistorian 2.8.585
CISA published ICS advisory ICSA-26-281-02 on 8 October 2026 for Grid Protection Alliance's openPDC (a phasor data concentrator for synchrophasor/PMU data in power grids) and openHistorian (a time-series historian). CVE-2026-100730 (CVSS 3.1 9.8): a service console interface deserialises client-supplied data; with Windows Authentication it needs a logged-in user, without it an unauthenticated network attacker can trigger deserialisation of an arbitrary object graph. CVE-2026-105278 (9.8): the published openPDC Docker image ships a fixed administrative credential with no forced change. CVE-2026-104629 (8.8): the component loader will build and run any specified type, so an authenticated user who can drop a file on the host can run code as the service account. CVE-2026-105281 (7.5) and CVE-2026-85479 (5.3): the internal and STTP data publishers accept unauthenticated connections by default, exposing the device and measurement topology or data exchange. CVE-2026-101022 (4.3): the Modbus connection feature can be pointed at any internal host to map the network. The new defaults bind the publishers to loopback only on new installs; upgraded systems keep their old settings. The vendor has not published fixes to the Docker image and advises against running those images in live environments. CISA lists no known public exploitation. Primary: CISA advisory (CSAF).
- Product
- Grid Protection Alliance openPDC (including Docker image) and openHistorian
- Versions
- openPDC before 2.9.482 (CVE-2026-104629: before 2.9.477); openHistorian before 2.8.585 (CVE-2026-104629: before 2.8.580); openPDC Docker image (no fix published)
- CVSS
- 9.8 (CVSS 3.1: CVE-2026-100730 and CVE-2026-105278)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade openPDC to 2.9.482 or later and openHistorian to 2.8.585 or later; turn on Windows Authentication; on upgraded installs rebind the internal and STTP data publishers to loopback by hand; firewall Modbus and block loopback and RFC 1918 targets; replace any openPDC Docker deployment with a patched native install.
Primary: CISA ICS advisory ICSA-26-281-02 — Grid Protection Alliance openPDC and openHistorian (8 Oct 2026) · Vendor: Grid Protection Alliance — openPDC releases · CVE: CVE-2026-100730, CVE-2026-105278, CVE-2026-104629, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022 · CISA CSAF — icsa-26-281-02.json
