CVE-2026-105281: Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Function

Published Oct 9, 2026
·
Updated

The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.

Affected Software

2 affected components
Grid Protection Alliance openPDC
Grid Protection Alliance openHistorian

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Verify the internal data publisher interface binding and change it from accepting connections on all interfaces to binding to the local loopback address, especially for existing installations upgraded from an earlier version.

    Grid Protection Alliance openPDC/openHistorian internal data publisher interface binding = local loopback address only

Event History

Oct 9, 2026
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed by default?

openPDC and openHistorian deployments with the internal data publisher reachable over the network are affected in the default configuration, because that interface accepts connections without authentication.

2

What does an attacker need to exploit this issue?

An attacker needs only network access to the internal data publisher interface. No authentication, privileges, or user interaction are required.

3

What information can be obtained through the exposed interface?

An unauthenticated attacker can retrieve the complete device and measurement topology of the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203