CVE-2026-100730
Received Received - Intake

Remote Code Execution in openPDC via Deserialization

Vulnerability report for CVE-2026-100730, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: ICS-CERT

Description

A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Grid Protection Alliance openPDC 0
Grid Protection Alliance openPDC 0
Grid Protection Alliance openPDC (Docker image) 0
Grid Protection Alliance openPDC (Docker image) 0
Grid Protection Alliance openHistorian 0
Grid Protection Alliance openHistorian 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a service console interface in openPDC and openHistorian that deserializes client-supplied data structures. On systems without Windows Authentication, unauthenticated attackers can exploit this to trigger deserialization of arbitrary objects, leading to remote code execution under the service account's privileges.

Detection Guidance

Detection requires checking for unauthorized deserialization attempts in openPDC or openHistorian service logs. Monitor for unexpected network traffic to the service console interface ports. Inspect Windows event logs for unusual process executions under the service account. No specific commands are provided in the context.

Impact Analysis

An attacker could gain control of the affected system by executing arbitrary code, potentially leading to data breaches, service disruption, or further network compromise. The impact depends on the privileges of the service account running the vulnerable software.

Compliance Impact

This vulnerability could lead to unauthorized access or data exfiltration, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance penalties, legal liabilities, and reputational damage if exploited.

Mitigation Strategies

Disable Windows Authentication if not required. Restrict network access to the service console interface. Apply vendor patches if available. Monitor for unusual deserialization activity in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100730. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart