SECURITYCRITICALCVE-2026-105278

CVE-2026-105278: openPDC Docker Image Ships Hardcoded Admin Credential

A fixed admin login baked into openPDC's Docker image, with no forced change, gives network attackers full control (CVSS 9.8).

Dylan H.

Security Team

October 10, 2026
5 min read
CVE-2026-105278: openPDC Docker Image Ships Hardcoded Admin Credential

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Grid Protection Alliance openPDC (Docker image) — versions prior to 2.9.477
  • Grid Protection Alliance openPDC (Docker image) — versions 2.9.477 through 2.9.481 (prior to 2.9.482)

Overview

A critical hardcoded-credential vulnerability, tracked as CVE-2026-105278, has been disclosed in the official Docker image for openPDC (open Phasor Data Concentrator), a real-time synchrophasor data-management platform from Grid Protection Alliance used across the electric power sector to collect and process PMU (phasor measurement unit) data from substations and transmission systems.

The published Docker image ships with a fixed administrative credential baked into the image itself, and the application does not force a password change on first login. Any attacker with network access to the management interface can authenticate with that known credential and walk away with full administrative control of the application. CISA's ICS-CERT published the advisory on 2026-10-09 as part of ICSA-26-281-02, assigning a CVSS 3.1 score of 9.8 (Critical).


Technical Details

FieldValue
CVE IDCVE-2026-105278
CVSS 3.1 Score9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 4.0 Score9.3 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-798 — Use of Hard-coded Credentials
Attack VectorNetwork — reachable from anywhere with access to the management interface
Privileges RequiredNone
User InteractionNone
Affected ComponentopenPDC Docker image, administrative login
Fixed VersionopenPDC 2.9.482 or later (do not use the published Docker image in production per vendor guidance — see Mitigation)
Reported ByShubham Raj ("Cipher") of Causal Security, via CISA

How It Works

openPDC's Docker image is built with a management web interface for administering the data-concentrator service. Rather than generating a random credential at first boot or forcing an operator to set one before the interface becomes usable, the image embeds a fixed administrative username and password directly in the build.

Because the credential is identical across every deployment of that image version, and there's no first-use enforcement requiring it to be changed, the attack is trivial:

  1. Attacker identifies a reachable openPDC management interface (default ports, internet-facing or improperly segmented internal network).
  2. Attacker authenticates using the publicly-known fixed credential shipped in the Docker image.
  3. Attacker now holds full administrative control of the openPDC instance — able to reconfigure data concentration settings, add or remove PMU connections, and potentially pivot into deeper grid-monitoring infrastructure.

No exploit sophistication is required beyond knowing (or discovering) the hardcoded value — this is a textbook CWE-798 case.


Impact Assessment

Impact AreaDescription
ConfidentialityHigh — full admin access exposes synchrophasor data streams and system configuration
IntegrityHigh — attacker can reconfigure data concentration, inject or drop PMU feeds
AvailabilityHigh — attacker with admin control can disable or disrupt the concentrator service
Sector ImpactEnergy — openPDC/openHistorian tooling is deployed worldwide for grid synchrophasor monitoring
Affected DeploymentsAny organization running the published openPDC Docker image below the fixed versions

Who Is At Risk

  • Utilities and grid operators running the published openPDC Docker image for synchrophasor/PMU data concentration
  • Any environment where the openPDC management interface is reachable from a broader network than strictly necessary — including accidental internet exposure
  • Organizations that assumed container deployment implied a unique or randomized credential, rather than a fixed one baked into the image

CISA's ICSA-26-281-02 bundles six CVEs affecting openPDC and openHistorian together, several considerably severe in their own right: an insecure-deserialization RCE (CVE-2026-100730, CVSS 9.8), two missing-authentication issues on the data publisher (CVE-2026-105281 and CVE-2026-85479), an SSRF (CVE-2026-101022), and an unsafe-reflection code-execution issue in the component loader (CVE-2026-104629). Operators patching for this hardcoded-credential flaw should address the full advisory, not just CVE-2026-105278 in isolation.


Mitigation

Immediate Actions

  • Upgrade to openPDC 2.9.482 or later (or openHistorian 2.8.585 or later, which receives the equivalent fix).
  • Immediately rotate any administrative credentials on existing deployments, regardless of version, since the fixed value may already be publicly known.
  • Grid Protection Alliance's own guidance, per the CISA advisory, is that it does not recommend production use of the published Docker images — evaluate whether a hardened, custom-built deployment is more appropriate for production synchrophasor infrastructure.

Detection Opportunities

  • Review authentication logs on openPDC management interfaces for logins using default or unexpected administrative usernames.
  • Audit for any configuration changes to PMU connections, data concentration settings, or publisher endpoints that administrators cannot account for.

Defence-in-Depth

  • Bind management and data-publisher interfaces to loopback or internal-only addresses — never expose openPDC's admin interface directly to the internet.
  • Restrict network access to openPDC hosts via firewall rules, and segment ICS/OT networks from general IT networks per standard grid-security practice.
  • Treat container images for ICS/OT software with the same credential-hygiene scrutiny as bare-metal installs — a Docker image is not inherently safer just because it's containerized.

Background

Grid Protection Alliance's openPDC and openHistorian are widely deployed across the electric power sector for collecting and archiving high-rate phasor measurement data used in real-time grid monitoring and historical analysis. CISA's advisory notes worldwide deployment across the energy sector, making credential-hygiene issues like this one more than a hypothetical concern — a hardcoded admin login on internet-reachable ICS tooling is exactly the kind of low-effort, high-impact entry point threat actors targeting critical infrastructure look for.

The advisory was reported to CISA by Shubham Raj ("Cipher") of Causal Security, and published alongside five other openPDC/openHistorian findings from the same research effort, spanning deserialization RCE, missing authentication on data publishers, SSRF, and unsafe reflection — a broad pattern of exposure in how these platforms are built and shipped by default.


References