Grid Protection Alliance openPDC and openHistorian
Reporting by CISA AlertsRead the original at cisa.gov
Executive Summary
Facts Only
openPDC versions less than 2.9.477 and openHistorian versions less than 2.8.580 are affected by CVE-2026-104629 (Deserialization of Untrusted Data), CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, and CVE-2026-101022.
openPDC (Docker image) versions less than 2.9.482 are affected by the same set of CVEs, plus CVE-2026-105278.
openHistorian versions less than 2.8.585 are affected by the same set of CVEs.
For specific CVE-2026-105281 and CVE-2026-85479, openPDC and openHistorian prior to their respective patch levels had an internal data publisher accepting unauthenticated network connections.
CVE-2026-101022 involves a Modbus connection feature on openPDC allowing connections to arbitrary internal hosts without restriction.
The remediation for deserialization flaws involves updating to openPDC 2.9.482+ and openHistorian 2.8.585+.
A mitigation for the Modbus-related vulnerabilities involves restricting network access using a firewall, disallowing loopback and private RFC 1918 address range connections unless explicitly required.
Full Take
From the original · CISA Alerts
View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: - openPDC <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) - openPDC (Docker image) <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278) - openHistorian <2.8.580…Read the full story at cisa.gov
Sentinel — Human
The text is highly structured, technical data consistent with a security advisory, suggesting it originates from official or carefully synthesized source material rather than general narrative writing.
