ZeroHour
Vendor

Inductive Automation

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

[Control Systems] Inductive Automation security advisory (AV26-892)

Canada's Cyber Centre relayed a CISA ICS advisory for an Inductive Automation Ignition vulnerability affecting versions up to 8.1.53.

The Canadian Centre for Cyber Security published control systems advisory AV26-892, noting that as of September 4, 2026, Inductive Automation is affected by a vulnerability in Ignition versions prior to or equal to 8.1.53. The advisory references CISA's ICS advisory (ICSA-26-246-06) and its CSAF file, and encourages users and administrators to review the linked resources and apply necessary updates as they become available. Ignition is a widely deployed industrial automation platform, so affected OT operators should patch promptly.

Canadian Centre for Cyber Security · 7d agoAdvisory

Inductive Automation Ignition

CISA reports a permissions flaw (CVE-2026-77393, CVSS 8.8) in Inductive Automation Ignition <=8.1.53 letting authenticated users create projects; fixed in 8.1.54.

CISA republished Inductive Automation's advisory for CVE-2026-77393, an incorrect default permissions issue (CWE-276) in Ignition 8.1.53 and earlier. The Gateway "Create Project Role(s)" setting shipped blank, allowing any authenticated user who can execute gateway scripts to create projects. Ignition 8.1.54 restricts project creation to Designer sessions and the 8.3 series is unaffected. CISA notes no known public exploitation of this vulnerability.

CISA Advisories · 12d agoAdvisoryCVE-2026-77393

Related CVEs

  • Incorrect default permissions in Inductive Automation Ignition 8.1 allow unauthorized project creation
    Ignition 8.1.53 and earlier shipped with the Gateway's "Create Project Role(s)" setting blank, so the role restriction it was meant to enforce was not applied (CWE-276, incorrect default permissions). An attacker needs network access and a low-privilege authenticated account that can execute gateway scripts; with those, a project-creation request against the Gateway succeeds without requiring Designer access. By creating a project, the attacker can gain high-impact access to the gateway per its CVSS 4.0 score of 8.7 (high confidentiality, integrity, and availability impact), making this useful as a foothold in OT/SCADA environments. All Ignition 8.1 deployments at or below 8.1.53 are affected; 8.1.54 restricts project creation to Designer sessions and the 8.3 series is not affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.5% (42nd percentile).
    · Inductive Automation Ignition 8.1 releases through 8.1.53 (fixed in 8.1.54; 8.3 series not affected)large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.