CVE-2026-85479: Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Function
The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Verify the interface binding configuration and change it from accepting connections on all interfaces to binding to the local loopback address only, especially for existing installations upgraded from an earlier version.
openPDC STTP-based data publisher interface interface binding = local loopback address only
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of Grid Protection Alliance openPDC or openHistorian that run the STTP-based data publisher with its default configuration are exposed if that interface is reachable by an attacker over the network.
What does an attacker need to exploit it?
An attacker needs network access to the STTP-based data publisher interface. No authentication or user interaction is required.
What can an attacker do after connecting?
An unauthenticated attacker can connect to the interface and exchange data with it. The provided information indicates confidentiality impact is limited and does not identify integrity or availability impact.