CVE-2026-105281: Grid Protection Alliance Openhistorian

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.

Affected products

Published 2026-10-09. Last modified 2026-10-09.