---
id: CVE-2026-104629
title: >-
  A component loading mechanism in openPDC and openHistorian will construct and
  run any specified type, which may be an invalid component to load
summary: >-
  A component loading mechanism in openPDC and openHistorian will construct and
  run any specified type, which may be an invalid component to load. An attacker
  with an authenticated user account and the ability to place a file on the host
  f…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-470
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:16:45.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104629'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
ingestedAt: '2026-10-09T15:00:31.363Z'
---

## Overview

A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
