CVE-2026-85479: Grid Protection Alliance Openhistorian

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.

Affected products

Published 2026-10-09. Last modified 2026-10-09.