CVE-2026-85479: Grid Protection Alliance Openhistorian
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.
Affected products
- Grid Protection Alliance Openhistorian: before 2.8.580 (fixed in 2.8.580); before 2.8.585 (fixed in 2.8.585)
- Grid Protection Alliance Openpdc: before 2.9.477 (fixed in 2.9.477); before 2.9.482 (fixed in 2.9.482)
- Grid Protection Alliance Openpdc Docker Image: before 2.9.477 (fixed in 2.9.477); before 2.9.482 (fixed in 2.9.482)
Published 2026-10-09. Last modified 2026-10-09.