CVE-2026-104629High· 8.8▾ TwilightA component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host f…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61925Medium· 6.5Astro is a web framework
CVE-2026-92415Medium· 6.9— Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client. A malicious WebDAV/DavEx server, or an attacker able to intercept the connection, can cause the client to instantia…
CVE-2026-106510High· 7.7Backstage is an open framework for building developer portals
CVE-2026-106439High· 8.5Hydra is a framework for elegantly configuring complex applications
CVE-2026-106440High· 7.8Hydra is a framework for elegantly configuring complex applications
CVE-2026-105782High· 7.5Scrapy is a high-level web crawling and scraping framework for Python