CVE-2026-100730
Received
Received - Intake
Remote Code Execution in openPDC via Deserialization
Vulnerability report for CVE-2026-100730, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-09
Last updated on: 2026-10-09
Assigner: ICS-CERT
Description
Description
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openHistorian 0 |
| Grid | Protection | Alliance openHistorian 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |