The Fixed Version Has No Release: CISA’s openPDC Advisory Patches the Grid in Nightly Builds
CISA published ICSA-26-281-02 on 8 October 2026, with the five CVE records reaching NVD the following afternoon. The subject is Grid Protection Alliance’s openPDC and openHistorian — the open-source phasor data concentrator and time-series historian that sit in the measurement path of electric transmission networks. CISA tags the advisory Energy sector, worldwide deployment.
The headline number is a CVSS 3.1 9.8 unauthenticated deserialization RCE. The more consequential detail is what the advisory offers as remediation: openPDC 2.9.482 and openHistorian 2.8.585 — version strings that have no GitHub release, no tag, and no installer page. The most recent tagged openPDC release is v2.9.318, from June 2024.
The five findings
Affected: openPDC below 2.9.477/2.9.482 and openHistorian below 2.8.580/2.8.585, plus the published openPDC Docker image. All five records were filed by ics-cert@hq.dhs.gov and sit at Awaiting Analysis in NVD with CISA’s own scores and no independent NVD rating.
- CVE-2026-100730 — CVSS 3.1 9.8 / CVSS 4.0 9.3, CWE-502. A service console interface on both products deserializes a client-supplied data structure, allowing an arbitrary object graph and code execution as the service account. The conditional matters: on systems using Windows Authentication the attacker must already be authenticated; without it, this is reachable by an unauthenticated network attacker. The 9.8 is scored for the latter case.
- CVE-2026-105278 — CVSS 3.1 9.8 / 4.0 9.3, CWE-798. The published openPDC Docker image ships a fixed administrative credential with no forced change on first use. Network access to the management interface is full administrative control.
- CVE-2026-104629 — 8.8 / 7.7, CWE-470. A component loading mechanism constructs and runs any specified type. An authenticated user who can place a file on the host runs arbitrary constructor code as the service account.
- CVE-2026-105281 — 7.5 / 8.7, CWE-306. openPDC’s internal data publisher accepts unauthenticated connections by default; an attacker retrieves the complete device and measurement topology of the system.
- CVE-2026-85479 — 5.3 / 6.9, CWE-306. The STTP-based data publisher likewise accepts unauthenticated connections and exchanges data.
- CVE-2026-101022 — 4.3 / 5.3, CWE-918. A Modbus connection feature accepts a caller-specified destination address and port with no restriction on internal targets, letting an authenticated user map the internal network by probing reachability.
CISA credits Shubham Raj (Cipher) of Causal Security with reporting all of them, and states that no known public exploitation specifically targeting these vulnerabilities has been reported.
Where the fix actually lives
We searched both repositories’ commit histories for the named fixed versions. Each resolves to exactly one commit, and both are automated build-number bumps:
- openPDC 2.9.482 → commit
da1407206, “Synchrophasor: Version change for build v2.9.482.0-master”, 18 July 2026. - openHistorian 2.8.585 → commit
eb8f406a5, “openHistorian: Version change for build v2.8.585.0-master”, 18 July 2026. - The lower bounds resolve the same way: openPDC 2.9.477 to a 2 July bump, openHistorian 2.8.580 to a 5 July bump.
So the remediation is real code, committed to master nearly three months before the advisory. What it is not is a release. Neither repository has tagged anything in the 2.9.4xx or 2.8.5xx range — openPDC’s tag list jumps from v2.9.318 (June 2024) straight to nothing, and openHistorian’s newest tag is v2.8.423-beta from October 2024. Both projects are plainly alive: openPDC’s master branch was pushed on 10 October 2026, and the build-number commits arrive weekly. The release channel is simply somewhere else.
That somewhere is the vendor’s nightly build directory. We retrieved the listings directly: openPDCSetup.msi was rebuilt on 9 October 2026 and openHistorianSetup.msi on 10 October 2026, both under a path labelled Beta. An operator following the advisory to the letter has to take a beta-labelled nightly MSI into a system that measures the transmission grid, because the version CISA names exists nowhere else. GitHub’s build-number commits confirm master is well past the fix — openPDC was at v2.9.496 on 9 October — but “install whatever master built last night” is a materially different instruction from “upgrade to 2.9.482”, and only the second one appears in the advisory.
The Docker image is the sharp edge
Three of the five findings carry a remediation status of “No fix planned” for the published Docker image, with the vendor’s stated reason quoted in the advisory: Grid Protection Alliance does not recommend production use of published Docker images in any case, and the fixes have not been published to the image.
That position is defensible as policy and unhelpful as reality. The image exists, it is public, and CVE-2026-105278 — the 9.8 hard-coded administrative credential — is specific to it. The Docker Hub tag listing we retrieved shows the newest published tag as v2.9.148, pushed 7 June 2024: more than two years stale, carrying a documented default admin credential and, per the advisory, three unfixed findings including the deserialization RCE. Anyone who pulled that image because it was the frictionless way to stand up openPDC is running a permanently unpatched build, and the advisory’s remedy for them is to stop using it.
We have seen this shape repeatedly this month — PraisonAI’s fixed version that was never published to PyPI, DB-GPT’s advisories that name no fixed version at all — but this is the first where the gap sits between a government advisory and the energy sector. The structured metadata says “patched in 2.9.482”. A procurement process, a compliance scan, or an asset-inventory tool reading that field will look for a release that does not exist.
The one fix that does not travel
CVE-2026-105281 and CVE-2026-85479 carry a caveat worth reading twice. The vendor fixed them by changing the default configuration to bind the data publisher to loopback only — and the advisory states plainly that this change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators are told to verify the binding explicitly.
This is the quiet failure mode of configuration-based remediation. Patch management verifies versions. It does not verify that a config file written in 2021 was revisited after an upgrade. An asset showing 2.9.482 in inventory can still be publishing its full device and measurement topology to any unauthenticated peer that connects, and nothing about the version number will reveal it. For CVE-2026-101022 there is no code fix at all — the advisory offers only firewall guidance and a recommendation to disallow connections to loopback and RFC 1918 ranges unless explicitly required.
What to do
- Establish what you are actually running before chasing version numbers. If your openPDC or openHistorian came from a GitHub release or a 2024-era installer, the advisory’s fixed versions are ahead of anything you have. Contact Grid Protection Alliance for a supported build path rather than assuming a tagged release exists.
- Treat the published Docker image as unpatched and unsupported. The newest public tag is v2.9.148 from June 2024, the vendor says no fix is planned for it, and it carries a hard-coded administrative credential. If it is in production, that is the finding to action first — and rotate that account wherever the image has run.
- Verify the publisher bindings by hand, on every host, after any upgrade. The loopback default does not apply to upgraded installations. Check the actual listening interfaces for the internal and STTP publishers; do not infer them from the version.
- Determine whether Windows Authentication is enabled. It is the difference between CVE-2026-100730 being an authenticated-user problem and an unauthenticated network RCE. That single setting moves the risk more than any other variable in this advisory.
- Apply the standard ICS network posture. CISA’s own guidance applies squarely: control systems off the internet, behind firewalls, isolated from business networks, remote access through maintained VPNs. For CVE-2026-101022 this is the entire remedy.
Verification note: the five CVE descriptions, CVSS 3.1 and 4.0 scores and vectors, CWE assignments, affected and fixed version ranges, per-product remediation statuses including the three “No fix planned” Docker entries, the upgraded-installation caveat on the loopback default, the researcher credit to Shubham Raj (Cipher) of Causal Security, and the no-known-exploitation statement were read directly from CISA advisory ICSA-26-281-02 and cross-checked against the NVD 2.0 API records (all five published 9 October 2026, status Awaiting Analysis, CISA scores only) on 10 October 2026. The commits behind openPDC 2.9.482, 2.9.477 and openHistorian 2.8.585, 2.8.580, the tag and release listings, and the October 2026 master-branch activity came from the GitHub API. The nightly-build MSI timestamps and the Beta path label were retrieved from Grid Protection Alliance’s published directory listing; the Docker Hub tag listing (newest v2.9.148, pushed 7 June 2024) came from the Docker Hub API. The reading that a beta nightly is a materially different instruction from a named version, and the comparison to recent advisories whose fixed versions were unobtainable, are our editorial assessment rather than statements by CISA or the vendor. We tested nothing and exploited nothing.
Sources:
- CISA — ICSA-26-281-02: Grid Protection Alliance openPDC and openHistorian (8 October 2026)
- NVD — CVE-2026-100730 (CWE-502, CVSS 3.1 9.8 / 4.0 9.3, Awaiting Analysis)
- NVD — CVE-2026-105278 (CWE-798, hard-coded credential in the published Docker image)
- NVD — CVE-2026-105281 (CWE-306, unauthenticated internal data publisher)
- GitHub — GridProtectionAlliance/openPDC releases (newest tag v2.9.318, June 2024)
- GitHub — GridProtectionAlliance/openHistorian releases (newest tag v2.8.423-beta, October 2024)
- Grid Protection Alliance — openPDC nightly build directory (Beta; MSI rebuilt 9 October 2026)