Skip to content

Executive Summary

Grid Protection Alliance products, specifically openPDC and openHistorian, are affected by multiple vulnerabilities related to data handling and network access. The affected versions depend on the specific vulnerability: for deserialization issues (CVE-2026-104629, etc.), openPDC versions prior to 2.9.482 and openHistorian versions prior to 2.8.585 are vulnerable. These vulnerabilities include risks like remote code execution via deserialization, unauthenticated access to internal data, and unrestricted Modbus network connections that could lead to internal network mapping. Reductions in privileges or exposure of topology information are associated with these flaws.

Facts Only

openPDC versions less than 2.9.477 and openHistorian versions less than 2.8.580 are affected by CVE-2026-104629 (Deserialization of Untrusted Data), CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, and CVE-2026-101022.
openPDC (Docker image) versions less than 2.9.482 are affected by the same set of CVEs, plus CVE-2026-105278.
openHistorian versions less than 2.8.585 are affected by the same set of CVEs.
For specific CVE-2026-105281 and CVE-2026-85479, openPDC and openHistorian prior to their respective patch levels had an internal data publisher accepting unauthenticated network connections.
CVE-2026-101022 involves a Modbus connection feature on openPDC allowing connections to arbitrary internal hosts without restriction.
The remediation for deserialization flaws involves updating to openPDC 2.9.482+ and openHistorian 2.8.585+.
A mitigation for the Modbus-related vulnerabilities involves restricting network access using a firewall, disallowing loopback and private RFC 1918 address range connections unless explicitly required.

Full Take

The structure of these disclosed vulnerabilities reveals a pattern centered on the security posture of data serialization and network boundaries within critical infrastructure systems. The sequence of CVEs—involving deserialization, missing authentication for critical functions, and server-side request forgery (SSRF)—suggests a systemic failure in validating input, both from external networks and internal services. The distinction between vendor fixes (applied to the core software) and mitigations (recommended practices like firewalling Modbus) highlights a necessary separation between patching code flaws and hardening operational exposure. Furthermore, the separate handling of the Docker image versus the base application points toward an asymmetric risk profile where containerized deployments introduce a non-patchable layer of uncertainty regarding vendor remediation. The consistent recommendation against using published Docker images suggests that automating deployment pipelines without full control over the artifact lifecycle introduces systemic risk, shifting responsibility from a simple version update to complete supply chain integrity. This implies a pattern where convenience (using public images) is prioritized over deep, verifiable security control, and the cost of this trade-off is borne by operators managing complex systems. The implications are that securing these environments requires not just patching known flaws but enforcing architectural separation and strict network segmentation regardless of the underlying software version.

From the original · CISA Alerts

View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: - openPDC <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022) - openPDC (Docker image) <2.9.477, <2.9.482 (CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278) - openHistorian <2.8.580…
Read the full story at cisa.gov

Sentinel — Human

Confidence

The text is highly structured, technical data consistent with a security advisory, suggesting it originates from official or carefully synthesized source material rather than general narrative writing.

Signals Detected
low severity: Sentence structure is highly structured (lists, tables) but the transition between sections flows logically based on technical enumeration.
low severity: High internal logical coherence specific to a vulnerability disclosure; no signs of general, impassioned argument.
medium severity: Perfect matching of CVEs, affected versions, and remediation steps across all entries suggests organized data extraction rather than organic writing.
low severity: The content is highly technical, relying on specific product names, version numbers, and CVEs. The structure strongly mirrors official vulnerability advisories.
Human Indicators
Specific legal notices and acknowledgments are present.
Recommendations reference external bodies (CISA) and specific policy URLs.
Grid Protection Alliance openPDC and openHistorian | Huntaegis