CVE-2026-105281
Received
Received - Intake
Unauthenticated Data Access in openPDC
Vulnerability report for CVE-2026-105281, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-09
Last updated on: 2026-10-09
Assigner: ICS-CERT
Description
Description
The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openHistorian 0 |
| Grid | Protection | Alliance openHistorian 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |