Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian

CISA reports six CVEs (CVSS 9.8) in openPDC and openHistorian that enable unauthenticated attackers to execute arbitrary code or perform SSRF. The flaws test the control objective of secure software lifecycle management, a key trust signal for energy‑sector auditors.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian

What It Is – CISA has identified six high‑severity CVEs (CVE‑2026‑104629, CVE‑2026‑100730, CVE‑2026‑105281, CVE‑2026‑85479, CVE‑2026‑101022, CVE‑2026‑105278) affecting openPDC and openHistorian versions prior to 2.9.482 and 2.8.585 respectively. The flaws include unsafe deserialization, missing authentication for critical functions, server‑side request forgery (SSRF), hard‑coded credentials, and unsafe reflection.

Exploitability – CVSS v3.1 base score 9.8 (critical). Exploits are publicly documented; unauthenticated network attackers can reach the vulnerable console when Windows Authentication is disabled.

Affected Products – Grid Protection Alliance openPDC (including Docker image) and openHistorian.

Why It Matters for Trust & Control Assurance

  • Control Objective – Secure Software Development & Vulnerability Management – The findings test an organization’s ability to maintain an up‑to‑date, securely configured software stack, a control that maps to the Protect function of NIST CSF 2.0.
  • Continuous evidence of patch deployment and configuration hardening is now a prerequisite for audit‑ready proof of a resilient energy‑grid operation.
  • Enterprise buyers increasingly demand demonstrable, real‑time assurance that critical‑infrastructure software is free from exploitable code paths.

Recommended Actions

  • Upgrade openPDC to ≥ 2.9.482 and openHistorian to ≥ 2.8.585 (or later).
  • Verify that Windows Authentication is enforced; disable the console interface if not required.
  • Conduct an immediate vulnerability scan of all grid‑control servers and remediate any residual findings.
  • Capture patch‑management evidence in your control‑monitoring platform to satisfy audit trails.

Source: CISA Advisory – ICSA‑26‑281‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →