CVE-2026-101022: Grid Protection Alliance Openhistorian
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.
Affected products
- Grid Protection Alliance Openhistorian: before 2.8.580 (fixed in 2.8.580); before 2.8.585 (fixed in 2.8.585)
- Grid Protection Alliance Openpdc: before 2.9.477 (fixed in 2.9.477); before 2.9.482 (fixed in 2.9.482)
- Grid Protection Alliance Openpdc Docker Image: before 2.9.477 (fixed in 2.9.477); before 2.9.482 (fixed in 2.9.482)
Published 2026-10-09. Last modified 2026-10-09.