Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces.
Vendor Workaround
Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it. | |
| Title | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-09T13:52:01.605Z
Reserved: 2026-10-05T16:54:01.625Z
Link: CVE-2026-85479
No data.
Status : Received
Published: 2026-10-09T14:17:23.983
Modified: 2026-10-09T14:17:23.983
Link: CVE-2026-85479
No data.
OpenCVE Enrichment
No data.