CVE-2026-85479
Received Received - Intake

STTP Data Publisher Authentication Bypass in openPDC

Vulnerability report for CVE-2026-85479, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: ICS-CERT

Description

The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Grid Protection Alliance openPDC 0
Grid Protection Alliance openPDC 0
Grid Protection Alliance openPDC (Docker image) 0
Grid Protection Alliance openPDC (Docker image) 0
Grid Protection Alliance openHistorian 0
Grid Protection Alliance openHistorian 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the STTP-based data publisher in openPDC, which accepts network connections without authentication in its default setup. An attacker can connect to this interface and exchange data without needing credentials.

Detection Guidance

Check for open network connections on ports typically used by openPDC (default ports may vary; inspect running services). Use network scanning tools like netstat or ss to identify unauthorized STTP-based data publisher connections. Example commands: 'netstat -tulnp | grep openPDC' or 'ss -tulnp | grep STTP'.

Impact Analysis

An unauthenticated attacker could potentially access or manipulate data transmitted through the openPDC interface, leading to unauthorized data exposure or integrity issues in the system.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and data protection, such as GDPR or HIPAA, by allowing unauthorized access to sensitive data.

Mitigation Strategies

Enable authentication on the STTP-based data publisher interface in openPDC configuration. Restrict network access using firewalls to allow only trusted IPs. Update openPDC to the latest version if patches are available. Monitor network traffic for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85479. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart