CVE-2026-100730: Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data

Published Oct 9, 2026
·
Updated

A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.

Affected Software

2 affected components
Grid Protection Alliance openPDC
Grid Protection Alliance openHistorian

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openPDC to a version that resolves this vulnerability.

    Fixed in 2.9.482
  2. Upgrade

    Upgrade openHistorian to a version that resolves this vulnerability.

    Fixed in 2.8.585

Event History

Oct 9, 2026
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit the affected service console interface?

Deployments without Windows Authentication expose the interface to unauthenticated network attackers. Where Windows Authentication is enabled, an attacker must already be authenticated to access the vulnerable function.

2

What level of access could successful exploitation provide?

An attacker can cause deserialization of an arbitrary object graph, which could result in remote code execution. Any resulting code would run with the privileges of the affected service account.

3

How can I determine whether my deployment has unauthenticated exposure?

Determine whether the affected openPDC or openHistorian system uses Windows Authentication for its service console interface. Systems not using Windows Authentication are reachable by an unauthenticated network attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203