← Back to CVE List
CVE-2026-100730NVD
Vulnerability Summary
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.
CVSS v4.0 Base Metrics — Score 9.3 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Grid Protection Alliance openPDC < 2.9.477
- Grid Protection Alliance openPDC < 2.9.482
- Grid Protection Alliance openPDC (Docker image) < 2.9.477
- Grid Protection Alliance openPDC (Docker image) < 2.9.482
- Grid Protection Alliance openHistorian < 2.8.580
- Grid Protection Alliance openHistorian < 2.8.585
- Grid Protection Alliance openPDC 2.9.477
- Grid Protection Alliance openPDC 2.9.482
- Grid Protection Alliance openPDC (Docker image) 2.9.477
- Grid Protection Alliance openPDC (Docker image) 2.9.482
- Grid Protection Alliance openHistorian 2.8.580
- Grid Protection Alliance openHistorian 2.8.585