CVE-2026-104629
Received Received - Intake

Component Loading Arbitrary Code Execution in openPDC

Vulnerability report for CVE-2026-104629, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: ICS-CERT

Description

A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Grid Protection Alliance openPDC 0
Grid Protection Alliance openPDC 0
Grid Protection Alliance openPDC (Docker image) 0
Grid Protection Alliance openPDC (Docker image) 0
Grid Protection Alliance openHistorian 0
Grid Protection Alliance openHistorian 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a component loading mechanism in openPDC and openHistorian that allows running any specified type. An attacker with authenticated access and file placement ability can exploit this to execute arbitrary constructor code with the privileges of the affected service account.

Impact Analysis

An attacker could gain control of the system running openPDC or openHistorian, leading to unauthorized code execution, data breaches, or service disruption. This could compromise sensitive data or system integrity.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR or HIPAA requirements for data protection and access control. Compliance may be compromised if sensitive data is exposed or mishandled.

Mitigation Strategies

Restrict authenticated user access to only necessary accounts and limit filesystem write permissions. Review and validate all component types loaded by openPDC and openHistorian to ensure they are legitimate and expected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104629. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart