# Grid Protection Alliance patches openPDC flaws

Published: 2026-10-08 · Severity: routine · Sectors: energy
Canonical: https://vorant.io/reports/789387d5-2fc2-57dd-a956-bd0d7a637efb/grid-protection-alliance-patches-openpdc-flaws

> CISA advisory details six vulnerabilities in openPDC and openHistorian, including unauthenticated RCE risk, patched in new vendor releases.

CISA published an ICS advisory covering Grid Protection Alliance's openPDC and openHistorian platforms, used for synchrophasor/grid telemetry collection in the energy sector worldwide. Six CVEs were disclosed, the most serious being CVE-2026-100730, a deserialization flaw in a service console interface that can lead to remote code execution under the service account's privileges; exploitation requires prior authentication only if Windows Authentication is enabled, otherwise it is reachable by an unauthenticated network attacker. Two additional issues (CVE-2026-105281, CVE-2026-85479) stem from internal data publisher and STTP interfaces that by default accept unauthenticated network connections, exposing device/measurement topology or allowing data exchange; fixes rebind these interfaces to loopback only for new installs, though existing upgraded installs retain the old binding and require manual reconfiguration. A Modbus connection feature (CVE-2026-101022) allows an authenticated user to probe arbitrary internal hosts/ports, enabling internal network reconnaissance (SSRF-style). The Docker image for openPDC ships a hardcoded administrative credential with no forced change (CVE-2026-105278), giving full admin control to anyone who can reach the management interface — this is unpatched in the Docker image, which the vendor does not recommend for production use. Finally, a component-loading mechanism (CVE-2026-104629) lets an authenticated user with file-placement ability run arbitrary constructor code under the service account.

Grid Protection Alliance has released openPDC 2.9.477/2.9.482 and openHistorian 2.8.580/2.8.585 with fixes for most issues; Docker images remain unpatched for several CVEs because the vendor discourages their production use. CISA states no known public exploitation of these vulnerabilities has been reported. Defenders running openPDC/openHistorian should patch promptly, explicitly verify and rebind network-facing interfaces (data publisher, STTP, management console) to loopback or restricted addresses, apply firewall restrictions to Modbus connectivity disallowing loopback/private-range targets, avoid production use of the Docker image, and rotate any default credentials.

## Mentioned in this report

- Vulnerabilities: CVE-2026-100730, CVE-2026-101022, CVE-2026-104629, CVE-2026-105278, CVE-2026-105281, CVE-2026-85479

## Detection guidance (public sample)

### openPDC or openHistorian Service Spawning Shell or Scripting Interpreter

ATT&CK: T1190

openPDC/openHistorian service process spawning a shell or LOLBin, consistent with RCE via deserialization or component-loading flaws running under the service account. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: openPDC or openHistorian Service Spawning Shell or Scripting Interpreter
description: Detects the openPDC or openHistorian service processes spawning command
  shells, scripting hosts or common LOLBins. Synchrophasor data collection services
  do not normally launch interactive interpreters, so this is consistent with post-exploitation
  of deserialization (console interface) or component-loading flaws running as the
  service account.
tags:
- attack.initial-access
- attack.t1190
- attack.execution
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
    - \openPDC.exe
    - \openHistorian.exe
  selection_child:
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
    - \rundll32.exe
    - \regsvr32.exe
    - \certutil.exe
    - \bitsadmin.exe
    - \whoami.exe
    - \net.exe
    - \net1.exe
  condition: selection_parent and selection_child
falsepositives:
- Administrators configuring custom openPDC output actions or adapters that intentionally
  invoke cmd.exe or PowerShell scripts
level: high
id: fc47bb7f-4476-549c-a2af-f632768df507
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02
```

### openPDC or openHistorian Connecting to Admin or Lateral Movement Service Ports

ATT&CK: T1046

openPDC/openHistorian process initiating connections to SMB, RPC, RDP, SSH or WinRM ports, indicating abuse of the Modbus connection feature for internal port scanning (SSRF-style). Repeated connections to many hosts or ports strengthen the signal. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: openPDC or openHistorian Connecting to Admin or Lateral Movement Service Ports
description: Detects the openPDC or openHistorian process making outbound connections
  to ports such as SMB, RPC, RDP, SSH, WinRM or VNC. The Modbus connection feature
  can be abused by an authenticated user to probe arbitrary internal hosts and ports
  (SSRF-style reconnaissance). A single hit is suspicious, and the same process hitting
  many destinations or ports in a short period is a strong indicator of scanning.
tags:
- attack.discovery
- attack.t1046
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    Image|endswith:
    - \openPDC.exe
    - \openHistorian.exe
    Initiated: 'true'
    DestinationPort:
    - 22
    - 23
    - 135
    - 139
    - 445
    - 3389
    - 5900
    - 5985
    - 5986
  condition: selection
falsepositives:
- Deployments where openPDC legitimately writes output to a file share over SMB
- Remote administration of the host performed from within the service context during
  maintenance
level: medium
id: 4a07a067-dc11-57f7-bf74-c5678c48acaa
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/789387d5-2fc2-57dd-a956-bd0d7a637efb/grid-protection-alliance-patches-openpdc-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
