CVE-2026-85479
Received
Received - Intake
STTP Data Publisher Authentication Bypass in openPDC
Vulnerability report for CVE-2026-85479, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-09
Last updated on: 2026-10-09
Assigner: ICS-CERT
Description
Description
The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openPDC (Docker image) 0 |
| Grid | Protection | Alliance openHistorian 0 |
| Grid | Protection | Alliance openHistorian 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |