Vulnerability intelligence
CVE-2026-100730
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Oct 9, 2026 · latest Oct 9, 2026
Coverage timeline
-
CISA Urges Patching of Critical Flaws in Energy Sector Softwaresecurityonline.info · Oct 9, 2026