ZCyberNews
中文
VulnerabilitiesCritical••4 min read•
CVE-2026-105278

CVE-2026-105278: openPDC Docker Image Ships Default Admin Login

CVE-2026-105278 (CVSS 9.8) leaves the published openPDC Docker image with a fixed administrative credential and no forced rotation, giving network-adjacent attackers full control.

Illustration of a Docker container icon with an unlocked padlock overlaid on a grid representing an electric power utility control network.

Executive Summary

The published Docker image for openPDC ships with a fixed administrative credential that is not rotated on first use, and an attacker who can reach the management interface can authenticate with it and take full administrative control of the application. The flaw is tracked as CVE-2026-105278 and carries a CVSS 9.8 base score, according to the NVD entry derived from a CISA ICS advisory (ICSA-26-281-02).

There is no named threat actor, no observed exploitation, and no IOC set in the source material. The practical exposure is straightforward: any openPDC deployment running the vendor-published container image with its management interface reachable from an untrusted network is effectively unauthenticated to anyone who knows or guesses the baked-in credential. openPDC is an open-source phasor data concentrator used in electric power and synchrophasor environments, so the affected population skews toward utilities and grid-adjacent operators rather than general enterprise IT.

Technical Analysis

The root cause is a credential-management failure in the container image, not a memory-safety or injection bug. The published Docker image for openPDC contains a fixed administrative credential, and the application does not force a change on first use. That combination means the credential persists across every deployment of the image unless an operator manually overrides it — a step the image does not require and does not prompt for.

The attack path is network-reachable authentication. An attacker with network access to the management interface can present the fixed credential and authenticate successfully, after which they hold full administrative control of the application. The advisory does not describe a privilege-escalation chain beyond that initial authentication; the default credential is sufficient on its own.

CISA's ICS advisory series covers industrial control systems, and the openPDC entry sits in that catalog. The NVD description is terse and does not enumerate affected image tags, digest hashes, or the specific credential value — those details would come from the vendor's own advisory or the image manifest, neither of which is present in the source material provided here. Defenders should not assume a particular tag is safe based on the CVE text alone; the affected artifact is the published Docker image as distributed, and version pinning should be verified against the vendor's advisory rather than inferred.

Because the flaw is a static credential rather than an exploitable code defect, patching is a matter of replacing the image with a corrected build or, where the vendor has not shipped one, removing the default credential before the interface is exposed. The CVSS 9.8 reflects the network-reachable, no-authentication-required, full-impact profile typical of default-credential findings in the ICS catalog.

Mitigations & Recommendations

The source material does not include vendor remediation steps, a fixed image tag, or a workaround beyond the description of the flaw itself, so the guidance below is scoped to what the advisory supports.

Treat any openPDC Docker deployment whose management interface is reachable from an untrusted network as potentially compromised. The fixed credential is the only barrier, and it is not deployment-specific, so exposure should be assumed rather than tested. Rotate the administrative credential immediately on every running instance and confirm the change took effect at the application layer, not just in the container environment. Where the credential cannot be changed, remove the management interface from untrusted networks entirely — segment it behind a management VLAN or an authenticated reverse proxy — until a corrected image is available.

Inventory openPDC container deployments and record which image digest is running. Because the CVE text does not name affected tags, the safe assumption is that any previously pulled vendor image is in scope until the vendor publishes a fixed build. Monitor authentication logs for successful admin logins from unexpected source addresses; a default-credential compromise will look like a normal successful authentication, so source-IP and timing anomalies are the only reliable signal. There are no IOCs or TTP mappings in the source material, so detection must be built from the application's own audit trail rather than from published indicators.

Stay Updated

Get the latest cybersecurity news delivered to your inbox.

Tags:#openpdc#docker#default-credentials#ics#cve-2026-105278#cisco

Related Articles