---
id: CVE-2026-105281
title: >-
  The internal data publisher on openPDC accepts network connections without
  authentication in its default configuration
summary: >-
  The internal data publisher on openPDC accepts network connections without
  authentication in its default configuration. An unauthenticated network
  attacker can connect to this interface and retrieve the complete device and
  measurement to…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T16:41:53.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105281'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
ingestedAt: '2026-10-09T15:00:31.364Z'
---

## Overview

The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
