CVE-2026-77393 PUBLISHED

Inductive Automation Ignition Incorrect Default Permissions

Assigner: icscert
Reserved: 20.08.2026 Published: 04.09.2026 Updated: 04.09.2026

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Inductive Automation
Product Ignition
Versions Default: unaffected
  • affected from 0 to 8.1.53 (incl.)
  • Version 8.1.54 is unaffected

Solutions

Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the "Create Project Role(s)" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability.

Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting "Create Project Role(s)" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings. https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3

Credits

  • Christopher Lusk of North Echo Security Research reported this vulnerability to Inductive Automation. finder
  • Elhussain Fathy (0xSphinx) independently reported this vulnerability and confirmed the fix. finder

References

Problem Types

  • CWE-276 CWE