CVE-2026-85479

Severity CVSS v4.0:
MEDIUM
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
09/10/2026
Last modified:
09/10/2026

Description

The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.