External risk intelligence

openPDC openHistorian Remote Code Execution via Object Deserialization

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-100730

The affected products, openPDC and openHistorian, are industrial control system management services. The vulnerability exists in a service console interface that is reachable by unauthenticated network attackers when Windows Authentication is not configured, making it commonly accessible as a network-reachable management surface in industrial deployment environments.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the service console interface of openPDC and openHistorian, allowing for potential remote code execution. This issue stems from the deserialization of client-supplied data, which, under certain configurations, can be exploited by unauthenticated network attackers to gain control of affected systems. The main concern is confirming the relevance and exposure of this vulnerability within your environment.

  • Arbitrary code execution via data deserialization.
  • Critical security flaw affecting industrial control systems.
  • Assess exposure and relevance to your operations.

Attack Path

How an attacker could exploit the issue

An attacker can reach a service console interface on openPDC and openHistorian, a component that processes client-supplied data. If Windows Authentication is not used, this interface is directly accessible over the network without any prior authentication, allowing an attacker to send specially crafted data that triggers the deserialization of an arbitrary object graph. This process can lead to remote code execution with the privileges of the service account.

  • Network accessible without authentication.
  • Deserializes client-supplied data.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact systems running openPDC and openHistorian by allowing an attacker to execute arbitrary code. The service console interface, which handles client-supplied data structures, is susceptible to deserialization of an untrusted object graph. This could lead to remote code execution with the privileges of the service account, potentially affecting system integrity and availability when Windows Authentication is not enforced.

  • System data and service behavior at risk.
  • Deserialization of arbitrary object graphs.
  • Remote code execution possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Platform or Infrastructure team is likely responsible for managing the openPDC and openHistorian services. The first practical step is to identify all instances of these services, confirm their network reachability and business criticality, and then locate the accountable owner to initiate a risk-based remediation plan.

  • Identify and confirm service ownership.
  • Verify network exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What are openPDC and openHistorian?

These are industrial software tools used to manage and store high-speed time-series data, often coming from power grid sensors. They act as critical management services that collect and process electrical system telemetry, serving as the backbone for monitoring operational technology environments.

What does deserialization mean in CVE-2026-100730?

Deserialization is the process of turning stored data back into an active object the software can use. This vulnerability, classified as CWE-502, occurs when the software blindly trusts incoming data. Because it fails to properly validate this data, an attacker can trick the system into creating harmful objects, which the computer then processes as legitimate instructions, leading to code execution.

What triggers the vulnerability in openPDC and openHistorian?

The trigger is a specially crafted data structure sent to the service console interface. On systems using Windows Authentication, the attack is blocked unless the attacker has already authenticated. However, if Windows Authentication is not configured, the interface accepts these malicious structures from any unauthenticated user on the network.

How do I know if this is a risk for my infrastructure?

According to Halo Surface Signal, these products are often used in industrial settings where network reachability is common. You should prioritize assets where the service console interface is accessible over the network. If your implementation lacks Windows Authentication, it is highly reachable and should be considered a priority for assessment.

What should I do first to manage this risk?

Start by performing an inventory to locate all running instances of openPDC and openHistorian in your environment. Once identified, verify if Windows Authentication is enabled on those services. Finally, engage your infrastructure team to review the business criticality of these systems and determine the appropriate security updates for your specific setup.

References