CVE-2026-105281: Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Function
The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Verify the internal data publisher interface binding and change it from accepting connections on all interfaces to binding to the local loopback address, especially for existing installations upgraded from an earlier version.
Grid Protection Alliance openPDC/openHistorian internal data publisher interface binding = local loopback address only
Event History
Frequently Asked Questions
Which deployments are exposed by default?
openPDC and openHistorian deployments with the internal data publisher reachable over the network are affected in the default configuration, because that interface accepts connections without authentication.
What does an attacker need to exploit this issue?
An attacker needs only network access to the internal data publisher interface. No authentication, privileges, or user interaction are required.
What information can be obtained through the exposed interface?
An unauthenticated attacker can retrieve the complete device and measurement topology of the system.