CVE-2026-105278

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets1 URL
Full discourse1 post
  • Severity Daily@severitydaily

    CISA (@CISAgov) scores a hard-coded admin credential in openPDC's published Docker image 9.8 and lists no fix planned — the remediation is to stop running the image. No exploitation reported. https://severitydaily.com/openpdc-icsa-26-281-02-cve-2026-105278-docker-no-fix-planned-2-9-482-missing/

    0000027
    33 followersView on X

Explore more