Unauthenticated Access Vulnerability in openPDC Data Publisher by CISA
CVE-2026-85479

6.9MEDIUM

What is CVE-2026-85479?

The STTP-based data publisher in openPDC is configured to accept network connections without the need for authentication. This opens the door for unauthenticated attackers to connect and interact with the data interface, potentially leading to unauthorized data exchange and manipulation. Organizations using openPDC need to be aware of this vulnerability and take necessary steps to secure their systems from potential exploits.

Affected Version(s)

openHistorian 0 < 2.8.580

openHistorian 0 < 2.8.585

openPDC 0 < 2.9.477

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shubham Raj (Cipher) of Causal Security reported this vulnerability to CISA.
.