Deserialization Vulnerability in openPDC and openHistorian by Voltage Security
CVE-2026-100730

9.3CRITICAL

What is CVE-2026-100730?

A vulnerability exists within the service console interface of openPDC and openHistorian that improperly handles client-supplied data structures. On systems utilizing Windows Authentication, an attacker must already be authenticated to exploit this function. Conversely, on systems without Windows Authentication, an unauthenticated network attacker can directly reach the vulnerable endpoint. This flaw allows attackers to trigger the deserialization of an arbitrary object graph, which could lead to remote code execution, executing commands with the privileges of the service account in use.

Affected Version(s)

openHistorian 0 < 2.8.580

openHistorian 0 < 2.8.585

openPDC 0 < 2.9.477

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shubham Raj (Cipher) of Causal Security reported this vulnerability to CISA.
.