---
id: CVE-2026-105278
title: >-
  The published Docker image for openPDC includes a fixed administrative
  credential with no forced change on first use
summary: >-
  The published Docker image for openPDC includes a fixed administrative
  credential with no forced change on first use. An attacker with network access
  to the management interface can authenticate using this credential and gain
  full admini…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T16:41:53.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105278'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
ingestedAt: '2026-10-09T16:02:33.376Z'
---

## Overview

The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
