{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openpdc-docker-image--2.9.482/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openPDC (\u003c 2.9.482)","openPDC Docker image (\u003c 2.9.482)","openHistorian (\u003c 2.8.585)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Grid Protection Alliance"],"content_html":"\u003cp\u003eGrid Protection Alliance has disclosed multiple high-severity vulnerabilities affecting openPDC and openHistorian software, widely used in the energy sector for phasor data management and historian functions. The vulnerabilities include CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, and CVE-2026-105278.\u003c/p\u003e\n\u003cp\u003eThe most critical flaw (CVE-2026-100730) involves insecure deserialization within the service console interface, which, in deployments without Windows Authentication, allows unauthenticated network attackers to achieve remote code execution (RCE) with the privileges of the service account. Other flaws include missing authentication on data publishing interfaces (CVE-2026-105281, CVE-2026-85479), which enable unauthorized access to system topology and measurement data. These vulnerabilities pose a significant threat to industrial control environments, as they may allow attackers to gain persistent access or manipulate grid monitoring data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in full system compromise, unauthorized exfiltration of sensitive energy grid measurement data, and potential disruption to monitoring capabilities. Organizations relying on these tools for critical infrastructure visibility are at risk of unauthorized access if internet-facing or unsegmented network interfaces remain exposed. There are no fixes planned for Docker image deployments, necessitating immediate mitigation for those instances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch affected systems by upgrading openPDC to version 2.9.482 or later and openHistorian to version 2.8.585 or later.\u003c/li\u003e\n\u003cli\u003eAudit network configurations to ensure internal data publisher interfaces are bound exclusively to the local loopback address. Existing installations do not automatically update this binding upon upgrade and require manual verification.\u003c/li\u003e\n\u003cli\u003eDiscontinue the use of published Docker images for production workloads, as the vendor does not provide security patches for these containers.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the service console interface and data publisher ports to trusted management subnets only.\u003c/li\u003e\n\u003cli\u003eEnable Windows Authentication for services where supported to provide an additional layer of defense against unauthenticated access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T17:06:43Z","date_published":"2026-10-08T17:06:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-grid-protection-alliance-vulns/","summary":"Grid Protection Alliance openPDC and openHistorian contain multiple critical vulnerabilities, including insecure deserialization and missing authentication, allowing unauthenticated remote attackers to execute code, exfiltrate system data, or manipulate data streams.","title":"Critical Vulnerabilities in Grid Protection Alliance openPDC and openHistorian","url":"https://feed.craftedsignal.io/briefs/2026-10-grid-protection-alliance-vulns/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenPDC Docker Image (\u003c 2.9.482)","version":"https://jsonfeed.org/version/1.1"}