Inductive Automation Ignition default-permissions flaw (CVE-2026-77393) lets authenticated users create projects; fixed in 8.1.54
CVE-2026-77393 (CVSS 3.1: 8.8 HIGH) affects Inductive Automation Ignition 8.1.53 and earlier: the Gateway 'Create Project Role(s)' setting shipped blank, so any authenticated user who can execute gateway scripts can create projects. Fix is Ignition 8.1.54,…
CISA republished Inductive Automation's advisory for CVE-2026-77393, an incorrect default permissions issue (CWE-276) in Ignition 8.1.53 and earlier, with a CVSS 3.1 base score of 8.8 (HIGH), network vector, and low privileges required. The Gateway 'Create Project Role(s)' setting shipped blank, allowing any authenticated user who can execute gateway scripts to create projects. Ignition 8.1.54 restricts project creation to Designer sessions, and the 8.3 series is unaffected. CISA notes no known public exploitation of the vulnerability and recommends isolating control systems and minimizing internet exposure. On 2026-09-08, the Canadian Centre for Cyber Security published control-systems advisory AV26-892, stating that as of September 4, 2026 Ignition versions prior to or equal to 8.1.53 are affected; it references CISA's ICS advisory ICSA-26-246-06 and its CSAF file and urges users and administrators to review the linked resources and apply updates. The two sources agree on affected versions (<=8.1.53) and the remediation; no conflicts were found.
- Vulnerability: CVE-2026-77393, incorrect default permissions (CWE-276) in Inductive Automation Ignition
- Affected versions: Ignition 8.1.53 and earlier (per both the CISA advisory and Canada's AV26-892, which cites the situation as of September 4, 2026)
- CVSS 3.1 base score: 8.8 (HIGH), network vector, low privileges required
- Impact: the Gateway 'Create Project Role(s)' setting shipped blank, so any authenticated user able to execute gateway scripts can create projects
- Fix: upgrade to Ignition 8.1.54, which restricts project creation to Designer sessions; the 8.3 series is unaffected
- Exploitation: no known public exploitation reported to CISA at this time
- Mitigation guidance: CISA recommends isolating control systems and minimizing internet exposure
- Canada's Centre for Cyber Security advisory AV26-892 (2026-09-08) references CISA ICS advisory ICSA-26-246-06 and its CSAF file and urges OT operators to apply updates
Coverage timelineoldest first · each row is one article
- · 13d agoInductive Automation Ignition
CISA Advisories· 28
CISA reports a permissions flaw (CVE-2026-77393, CVSS 8.8) in Inductive Automation Ignition <=8.1.53 letting authenticated users create projects; fixed in 8.1.54.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-77393 | Incorrect default permissions in Inductive Automation Ignition 8.1 allow unauthorized project creation Ignition 8.1.53 and earlier shipped with the Gateway's "Create Project Role(s)" setting blank, so the role restriction it was meant to enforce was not applied (CWE-276, incorrect default permissions). An attacker needs network access and a low-privilege authenticated account that can execute gateway scripts; with those, a project-creation request against the Gateway succeeds without requiring Designer access. By creating a project, the attacker can gain high-impact access to the gateway per its CVSS 4.0 score of 8.7 (high confidentiality, integrity, and availability impact), making this useful as a foothold in OT/SCADA environments. All Ignition 8.1 deployments at or below 8.1.53 are affected; 8.1.54 restricts project creation to Designer sessions and the 8.3 series is not affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.5% (42nd percentile). Do: Upgrade Ignition 8.1 to 8.1.54 or later, which restricts project creation to Designer sessions. As an interim mitigation, set the Gateway "Create Project Role(s)" setting to a restricted role and review which authenticated users have gateway script execution rights. Audit existing projects for any unexpected creations made by non-Designer users. | 8.7 | <1% |
| large≈10,000–100,000 systems (tens of thousands of internet-exposed Ignition gateways, with a larger total 8.1 installed base) |