CVE-2026-104629
Received
Received - Intake
Component Loading Arbitrary Code Execution in openPDC
Vulnerability report for CVE-2026-104629, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-09
Last updated on: 2026-10-09
Assigner: ICS-CERT
Description
Description
A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openHistorian 0 |
| Grid | Protection | Alliance openHistorian 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-470 | The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code. |