Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian
What It Is – CISA has identified six high‑severity CVEs (CVE‑2026‑104629, CVE‑2026‑100730, CVE‑2026‑105281, CVE‑2026‑85479, CVE‑2026‑101022, CVE‑2026‑105278) affecting openPDC and openHistorian versions prior to 2.9.482 and 2.8.585 respectively. The flaws include unsafe deserialization, missing authentication for critical functions, server‑side request forgery (SSRF), hard‑coded credentials, and unsafe reflection.
Exploitability – CVSS v3.1 base score 9.8 (critical). Exploits are publicly documented; unauthenticated network attackers can reach the vulnerable console when Windows Authentication is disabled.
Affected Products – Grid Protection Alliance openPDC (including Docker image) and openHistorian.
Why It Matters for Trust & Control Assurance
- Control Objective – Secure Software Development & Vulnerability Management – The findings test an organization’s ability to maintain an up‑to‑date, securely configured software stack, a control that maps to the Protect function of NIST CSF 2.0.
- Continuous evidence of patch deployment and configuration hardening is now a prerequisite for audit‑ready proof of a resilient energy‑grid operation.
- Enterprise buyers increasingly demand demonstrable, real‑time assurance that critical‑infrastructure software is free from exploitable code paths.
Recommended Actions
- Upgrade openPDC to ≥ 2.9.482 and openHistorian to ≥ 2.8.585 (or later).
- Verify that Windows Authentication is enforced; disable the console interface if not required.
- Conduct an immediate vulnerability scan of all grid‑control servers and remediate any residual findings.
- Capture patch‑management evidence in your control‑monitoring platform to satisfy audit trails.
Source: CISA Advisory – ICSA‑26‑281‑02