As cited
Copy frozen at (site build).
vulnerabilities
Inductive Automation Ignition
CVE-2026-77393 affects Inductive Automation Ignition versions 8.1.53 and earlier, where the "Create Project Role(s)" setting shipped blank, allowing any authenticated user to create projects. The vulnerability stems from incorrect default permissions rather than a flaw in access control itself. Inductive Automation released version 8.1.54 to restrict project creation to Designer sessions and no longer depend on the configuration setting.
Why it matters: Organizations running Ignition 8.1.53 or earlier in critical manufacturing and energy environments must upgrade to 8.1.54 or populate the "Create Project Role(s)" setting to prevent unauthorized project creation by authenticated users.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Inductive Automation Ignition
Inductive Automation Ignition versions 8.1.53 and earlier contain CVE-2026-77393, a vulnerability that allows any authenticated user with gateway script execution permissions to create projects because the "Create Project Role(s)" setting shipped blank. The company has released version 8.1.54 and later to restrict project creation to Designer sessions, and users on earlier versions can mitigate the issue by configuring the role-based access control setting.
Why it matters: Organizations deploying Ignition in critical manufacturing and energy sectors must patch to version 8.1.54 or later, or manually configure role restrictions, to prevent unauthorized project creation by authenticated attackers.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Inductive Automation Ignition
Inductive Automation Ignition versions 8.1.53 and earlier contain CVE-2026-77393, a vulnerability that allows any authenticated user with gateway script execution permissions to create projects because the "Create Project Role(s)" setting shipped blank. The company has released version 8.1.54 and later to restrict project creation to Designer sessions, and users on earlier versions can mitigate the issue by configuring the role-based access control setting.
Why it matters: Organizations deploying Ignition in critical manufacturing and energy sectors must patch to version 8.1.54 or later, or manually configure role restrictions, to prevent unauthorized project creation by authenticated attackers.
- Source published
- First seen by Cybersecurity Tracker