CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Inductive Automation Ignition

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5651

As cited

Copy frozen at (site build).

vulnerabilities

Inductive Automation Ignition

CVE-2026-77393 affects Inductive Automation Ignition versions 8.1.53 and earlier, where the "Create Project Role(s)" setting shipped blank, allowing any authenticated user to create projects. The vulnerability stems from incorrect default permissions rather than a flaw in access control itself. Inductive Automation released version 8.1.54 to restrict project creation to Designer sessions and no longer depend on the configuration setting.

Why it matters: Organizations running Ignition 8.1.53 or earlier in critical manufacturing and energy environments must upgrade to 8.1.54 or populate the "Create Project Role(s)" setting to prevent unauthorized project creation by authenticated users.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Inductive Automation Ignition

Inductive Automation Ignition versions 8.1.53 and earlier contain CVE-2026-77393, a vulnerability that allows any authenticated user with gateway script execution permissions to create projects because the "Create Project Role(s)" setting shipped blank. The company has released version 8.1.54 and later to restrict project creation to Designer sessions, and users on earlier versions can mitigate the issue by configuring the role-based access control setting.

Why it matters: Organizations deploying Ignition in critical manufacturing and energy sectors must patch to version 8.1.54 or later, or manually configure role restrictions, to prevent unauthorized project creation by authenticated attackers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Inductive Automation Ignition

Inductive Automation Ignition versions 8.1.53 and earlier contain CVE-2026-77393, a vulnerability that allows any authenticated user with gateway script execution permissions to create projects because the "Create Project Role(s)" setting shipped blank. The company has released version 8.1.54 and later to restrict project creation to Designer sessions, and users on earlier versions can mitigate the issue by configuring the role-based access control setting.

Why it matters: Organizations deploying Ignition in critical manufacturing and energy sectors must patch to version 8.1.54 or later, or manually configure role restrictions, to prevent unauthorized project creation by authenticated attackers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary