ZeroHour

CVE-2026-77393

large

Incorrect default permissions in Inductive Automation Ignition 8.1 allow unauthorized project creation

CVSS 4.0
8.7 high
EPSS
<1%p42
Published
()
Modified
AI analysis

Ignition 8.1.53 and earlier shipped with the Gateway's "Create Project Role(s)" setting blank, so the role restriction it was meant to enforce was not applied (CWE-276, incorrect default permissions). An attacker needs network access and a low-privilege authenticated account that can execute gateway scripts; with those, a project-creation request against the Gateway succeeds without requiring Designer access. By creating a project, the attacker can gain high-impact access to the gateway per its CVSS 4.0 score of 8.7 (high confidentiality, integrity, and availability impact), making this useful as a foothold in OT/SCADA environments. All Ignition 8.1 deployments at or below 8.1.53 are affected; 8.1.54 restricts project creation to Designer sessions and the 8.3 series is not affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.5% (42nd percentile).

What to do: Upgrade Ignition 8.1 to 8.1.54 or later, which restricts project creation to Designer sessions. As an interim mitigation, set the Gateway "Create Project Role(s)" setting to a restricted role and review which authenticated users have gateway script execution rights. Audit existing projects for any unexpected creations made by non-Designer users.

Affected
Inductive Automation Ignition8.1 releases through 8.1.53 (fixed in 8.1.54; 8.3 series not affected)
Estimated exposure
large≈10,000–100,000 systems (tens of thousands of internet-exposed Ignition gateways, with a larger total 8.1 installed base) — Public internet-wide scans (e.g., Shodan/Censys) typically show tens of thousands of exposed Inductive Automation Ignition gateways, and because every 8.1 release up to 8.1.53 is affected, all pre-8.1.54 installations are in scope, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

Weakness
CWE-276
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Inductive Automation Ignition

CISA reports a permissions flaw (CVE-2026-77393, CVSS 8.8) in Inductive Automation Ignition <=8.1.53 letting authenticated users create projects; fixed in 8.1.54.

CISA republished Inductive Automation's advisory for CVE-2026-77393, an incorrect default permissions issue (CWE-276) in Ignition 8.1.53 and earlier. The Gateway "Create Project Role(s)" setting shipped blank, allowing any authenticated user who can execute gateway scripts to create projects. Ignition 8.1.54 restricts project creation to Designer sessions and the 8.3 series is unaffected. CISA notes no known public exploitation of this vulnerability.

CISA Advisories · 12d agoAdvisoryCVE-2026-77393