Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-100730: openPDC and openHistorian may let attackers run code

CVE-2026-100730 · published today
Summary

The openPDC and openHistorian services can process data sent from a client without properly checking it. If the system is not using Windows Authentication, anyone on the network could send crafted data that makes the service execute unwanted code with the service's privileges; with Windows Authentication, only already logged‑in users could do this. Apply the vendor's security update, limit network access to these services, and use Windows Authentication wherever possible.

What to do
  • Update grid protection alliance openpdc to version 2.9.477 or later.
  • Update grid protection alliance openpdc (docker image) to version 2.9.477 or later.
  • Update grid protection alliance openhistorian to version 2.8.580 or later.
Affected software
VendorProductAffected versions
grid protection alliance openpdc < 2.9.477
grid protection alliance openpdc (docker image) < 2.9.477
grid protection alliance openhistorian < 2.8.580
Original advisory text
Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.3 Critical
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen9 Oct 2026
Sources
CVE-2026-100730 · MITRE
Track software like this
Free during beta