External risk intelligence

openPDC Docker Image Includes Hardcoded Administrator Credentials

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105278

The vulnerability involves a management interface for openPDC, a phasor data concentrator. These industrial control system components are frequently deployed to aggregate data across network segments, and management interfaces for such gateways or concentrators are commonly configured to be reachable over networks for remote administration and monitoring.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The published Docker image for openPDC includes a fixed administrative credential, allowing unauthorized access to gain full administrative control of the application if the management interface is accessible. This vulnerability could allow an attacker to compromise the application's administrative functions. The main concern is confirming relevance and exposure.

  • Fixed credential grants full admin control.
  • Critical infrastructure component requires attention.
  • Understand relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with network access to openPDC's management interface can use a default administrative credential to gain full control of the application. This is possible because the published Docker image includes a hardcoded password that is not changed on first use. Once authenticated, the attacker can perform any administrative action within the application.

  • Network access required.
  • Default credential allows login.
  • Full administrative control gained.

Live Threat

Current exploitation, exposure, and threat context

An attacker with network access to the management interface could gain full administrative control of the openPDC application by using a fixed, default credential. This could affect the application's service behavior and any system data it manages.

  • Application administrative control.
  • Authentication via default credentials.
  • Potential for unauthorized application control.

Operational Fix

Recommended remediation, mitigation, and detection steps

The openPDC management interface is a likely target for compromise due to its network accessibility and critical function in data aggregation. Infrastructure or platform teams responsible for openPDC deployments should prioritize identifying all instances of this software. Once located, confirm network reachability and business criticality to assign ownership and plan remediation based on the assessed risk.

  • Infrastructure or platform teams own this.
  • Verify network exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is openPDC and why is it used?

openPDC, or the Open Phasor Data Concentrator, is software used in industrial control systems to collect and synchronize high-speed time-series data from sensors across power grids. It serves as a central hub for aggregating measurements from various locations, enabling real-time monitoring and analysis of grid performance. Because it handles critical data streams, ensuring the security of its management functions is vital for maintaining the integrity of these industrial monitoring networks.

How does CVE-2026-105278 work as a security weakness?

This vulnerability is classified as CWE-798, which refers to the use of hardcoded credentials. In this specific case, the openPDC Docker image contains a built-in administrative password that does not require the user to change it upon first launch. Because this fixed credential is standard across deployments, it functions like a master key. Anyone who knows this default password can bypass standard login security and gain full administrative privileges over the application.

Does this CVE affect me if my interface is not on the internet?

The vulnerability requires network access to the management interface to trigger. While internet-facing instances are at the highest risk, the flaw is not limited solely to public web access. Anyone with access to the local or internal network segment where the management interface is reachable could potentially use the hardcoded credential. It is not triggered by application usage alone, but specifically by an attacker reaching the administrative login page.

Is my openPDC deployment at high risk?

According to Halo Surface Signal, this vulnerability is considered likely to be relevant because openPDC is often deployed to aggregate data across multiple network segments. Because these management interfaces are frequently configured to remain reachable for remote administration and monitoring, they are often accessible to broader network segments. If your instance is reachable over the network, it faces a high risk of unauthorized administrative takeover.

What should I do if I use the affected Docker image?

Your first step is to identify all instances of openPDC running within your infrastructure to establish an accurate inventory. Once identified, verify which management interfaces are reachable over your network and assess the business criticality of those specific assets. Use this information to assign ownership to the relevant teams and plan your response, ensuring that the hardcoded credentials are addressed and access is properly restricted.

References