Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces.
Vendor Workaround
Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system. | |
| Title | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-09T13:49:06.352Z
Reserved: 2026-10-05T16:54:01.621Z
Link: CVE-2026-105281
No data.
Status : Awaiting Analysis
Published: 2026-10-09T14:17:11.450
Modified: 2026-10-09T16:41:53.540
Link: CVE-2026-105281
No data.
OpenCVE Enrichment
Updated: 2026-10-09T16:45:09Z
-
CWE-306
Missing Authentication for Critical Function