VYPR
advisoryPublished Oct 8, 2026· 1 source

CISA Warns of Critical Vulnerabilities in Grid Protection Alliance Software

CISA has issued an advisory detailing multiple critical vulnerabilities in Grid Protection Alliance's openPDC and openHistorian software, potentially allowing unauthenticated remote code execution.

The Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory concerning several vulnerabilities affecting Grid Protection Alliance's (GPA) openPDC and openHistorian software. These industrial control system (ICS) components are widely used in the energy sector for managing and analyzing power grid data. The identified flaws, which impact versions prior to openPDC 2.9.482 and openHistorian 2.8.585, pose a significant risk to the operational integrity and security of critical infrastructure.

The vulnerabilities include deserialization of untrusted data, missing authentication for critical functions, server-side request forgery (SSRF), use of hard-coded credentials, and the use of externally-controlled input to select classes or code, also known as 'unsafe reflection.' One of the most severe, CVE-2026-100730, involves a service console interface that deserializes client-supplied data. On systems without Windows Authentication, this flaw is reachable by unauthenticated network attackers, potentially leading to remote code execution under the privileges of the affected service account. The CVSS v3.1 score for this vulnerability is a critical 9.8.

Another significant vulnerability, CVE-2026-105281, affects an internal data publisher on openPDC. In its default configuration, this interface accepts network connections without authentication. This allows an unauthenticated attacker to connect and retrieve the complete device and measurement topology of the system, providing attackers with crucial information for further exploitation or reconnaissance. While GPA has updated the default configuration to bind this interface to the local loopback address only for new installations, existing installations that have been upgraded may retain their previous, less secure configurations, requiring manual verification.

Grid Protection Alliance has addressed these issues by implementing additional validation into the serialization logic in openPDC version 2.9.482 and later, and openHistorian version 2.8.585 and later. For systems utilizing Windows Authentication, additional protection is provided as attackers must already be authenticated to exploit certain flaws. However, for the openPDC Docker image, no fix is currently planned, as GPA does not recommend production use of its published Docker images.

CISA has assigned multiple CVE identifiers to these vulnerabilities, including CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, and CVE-2026-105278 for the openPDC Docker image. The widespread deployment of openPDC and openHistorian across the energy sector, with installations worldwide, underscores the potential impact of these vulnerabilities. Operators of critical infrastructure relying on these systems are strongly urged to apply the vendor-provided patches and verify their configurations.

The advisory highlights the ongoing challenges in securing operational technology (OT) environments, where legacy systems and specialized software often present unique security hurdles. The combination of deserialization flaws, authentication bypasses, and SSRF vulnerabilities creates a potent attack vector that could disrupt essential services. The critical nature of the energy sector means that successful exploitation could have cascading effects on grid stability and reliability.

Organizations using affected versions of openPDC and openHistorian should prioritize updating to the patched versions as soon as possible. For existing installations, it is crucial to manually review and secure network interfaces that might be exposed. CISA's advisory serves as a critical alert, emphasizing the need for continuous vigilance and proactive security management within ICS environments to prevent potential disruptions and ensure the resilience of the nation's energy infrastructure.

Synthesized by Vypr AI