IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Inductive Automation Ignition

HIGH
CVSS 8.8
Date 2026-09-03T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow any authenticated user to create projects.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-77393 8.8 high
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
Inductive Automation Unknown hmi
L2
7.7.2

// Remediations (3)

Mitigation: For more information, see the publication at the Inductive Automation Trust Center.
For more information, see the publication at the Inductive Automation Trust Center.
Mitigation: Inductive Automation has determined that this issue is a default-value configuration, not a flaw in
Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the "Create Project Role(s)" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability.
Mitigation: Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which
Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting "Create Project Role(s)" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings.

// References