CVE-2026-101022: Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF)
A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs to be authenticated to the affected product and able to use its Modbus connection feature. No user interaction is required, and the vulnerable behavior is reachable over the network.
What can an attacker accomplish?
The attacker can supply arbitrary internal destination addresses and ports for connection attempts. The observed reachability of those destinations can be used to identify reachable internal systems and map the internal network.
What evidence would indicate attempted exploitation?
Look for Modbus connection requests made by authenticated users to unusual, unauthorized, or numerous internal addresses and ports. Repeated connection attempts across multiple destinations may indicate internal network discovery activity.