CVE-2026-104629: Grid Protection Alliance Openhistorian
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.
Affected products
- Grid Protection Alliance Openhistorian: before 2.8.580 (fixed in 2.8.580); before 2.8.585 (fixed in 2.8.585)
- Grid Protection Alliance Openpdc: before 2.9.477 (fixed in 2.9.477); before 2.9.482 (fixed in 2.9.482)
- Grid Protection Alliance Openpdc Docker Image: before 2.9.477 (fixed in 2.9.477); before 2.9.482 (fixed in 2.9.482)
Published 2026-10-09. Last modified 2026-10-09.