Update openPDC to version 2.9.482 or later and openHistorian to version 2.8.585 or later. For existing installations, verify and configure the data publisher interface to bind to the local loopback address only. Docker image users should avoid production use of published images; GPA does not recommend their use. Review network exposure of service console interfaces and disable unnecessary remote access where possible.
Quick answers
What is CVE-2026-85479?
Update openPDC to version 2.9.482 or later and openHistorian to version 2.8.585 or later. For existing installations, verify and configure the data publisher interface to bind to the local loopback address only. Docker image users should avoid production use of published images; GPA does not recommend their use. Review network exposure of service console interfaces and disable unnecessary remote access where possible.
How severe is CVE-2026-85479?
critical, CVSS 9.8
Is CVE-2026-85479 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-85479 be mitigated?
Update openPDC to version 2.9.482 or later and openHistorian to version 2.8.585 or later. For existing installations, verify and configure the data publisher interface to bind to the local loopback address only. Docker image users should avoid production use of published images; GPA does not recommend their use. Review network exposure of service console interfaces and disable unnecessary remote access where possible.
CVSS
9.8
Vendor
Grid Protection Alliance
Published
Oct 9, 2026 · 02:30
Patch
Unknown / not confirmed
Affected products
openPDC, openHistorian, openPDC (Docker image)
Mitigation
Update openPDC to version 2.9.482 or later and openHistorian to version 2.8.585 or later. For existing installations, verify and configure the data publisher interface to bind to the local loopback address only. Docker image users should avoid production use of published images; GPA does not recommend their use. Review network exposure of service console interfaces and disable unnecessary remote access where possible.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory detailing six vulnerabilities in Grid Protection Alliance openPDC and openHistorian software. The flaws, disclosed October 8, 2026, span deserialization of untrusted data, missing authentication for critical functions, server-side request forgery, use of hard-coded credentials, and unsafe reflection. CVSS v3.1 base scores reach 9.8, classifying them as critical. The vulnerabilities affect on-premises versions of openPDC prior to 2.9.482 and openHistorian prior to 2.8.585. A separate set of issues impacts the openPDC Docker image, for which the vendor has stated no fix is planned and does not recommend production use.