Multiple critical openPDC openHistorian vulnerabilities threaten energy sector critical infrastructure. Six distinct flaws expose systems to remote code execution and administrative takeover. Defenders must apply vendor patches immediately.
- Total: 6 CVEs
- Severity: 2 Critical · 2 High · 2 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-100730
- Action: Apply the latest security updates now
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-100730 | 9.8 | and openHistorian Deserialization of Untrusted Data | 2.9.477, 2.9.482, 2.8.580 (+1) | Not exploited |
| CVE-2026-105278 | 9.8 | Use of Hard-coded Credentials | 2.9.477, 2.9.482 | Not exploited |
| CVE-2026-104629 | 8.8 | and openHistorian Use of Externally-Controlled Input to Select Classes or Code | 2.9.477, 2.9.482, 2.8.580 (+1) | Not exploited |
| CVE-2026-105281 | 7.5 | and openHistorian Missing Authentication for Critical Function | 2.9.477, 2.9.482, 2.8.580 (+1) | Not exploited |
| CVE-2026-85479 | 5.3 | and openHistorian Missing Authentication for Critical Function | 2.9.477, 2.9.482, 2.8.580 (+1) | Not exploited |
| CVE-2026-101022 | 4.3 | and openHistorian Server-Side Request Forgery (SSRF) | 2.9.477, 2.9.482, 2.8.580 (+1) | Not exploited |
Impact on Critical Infrastructure
These products manage critical energy data worldwide. Therefore, a successful attack on these tools compromises core grid operations. Unpatched openPDC openHistorian vulnerabilities put facilities at extreme risk. Furthermore, CISA warns about the severity of these bugs. According to the agency, “Successful exploitation of these vulnerabilities could allow an attacker to gain administrative control of the system, execute arbitrary code, access sensitive operational data, or map the internal network.” This official security advisory makes patching an urgent priority. Fortunately, no known public exploitation specifically targeting these vulnerabilities has been reported yet.
Attack Mechanisms
The most severe bug allows deserialization of untrusted data. Specifically, an unauthenticated attacker sends a malicious data structure to the service console. Consequently, the application processes this input blindly. This action triggers remote code execution under the service account privileges. Similarly, another flaw involves missing authentication on the internal data publisher. Hackers connect to this interface directly without credentials. Then, they extract the complete device and measurement topology. Additionally, unsafe reflection lets authenticated users run arbitrary constructor code. Finally, a Server-Side Request Forgery flaw enables attackers to map internal networks.
Vulnerable Software Releases
These flaws impact several software versions. First, Grid Protection Alliance openPDC versions prior to 2.9.482 contain these flaws. Second, openHistorian versions prior to 2.8.585 are vulnerable. Also, the Docker image for openPDC suffers from hard-coded credentials.
Mitigation Strategies
System administrators must upgrade openPDC to version 2.9.482. Likewise, they need to update openHistorian to version 2.8.585. Grid Protection Alliance strongly advises against using their Docker images for production. Therefore, users should avoid the Docker versions entirely. Additionally, teams must locate control system networks behind firewalls. Finally, defenders should isolate these devices from general business networks. CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!