CVE-2026-77393

8.8

Inductive Automation · Ignition

A misconfigured default setting in Inductive Automation Ignition allows any authenticated user with gateway script execution capabilities to create projects, potentially leading to unauthorized system changes.

Executive summary

A critical authorization vulnerability in Inductive Automation Ignition allows authenticated users to create projects due to a blank default configuration, posing a significant risk of unauthorized system modification.

Vulnerability

The vulnerability involves a default-value configuration issue (CWE-276) where the Gateway Create Project Role(s) setting was left blank, effectively granting project creation permissions to any authenticated user capable of executing gateway scripts. This allows low-privileged authenticated users to perform actions typically reserved for administrators.

Business impact

The ability for unauthorized users to create projects can lead to severe operational disruption, unauthorized data manipulation, and full control over the industrial control system environment. Given the CVSS score of 8.8, this vulnerability represents a high risk to business integrity and system availability, as it facilitates unauthorized configuration changes that could be leveraged for malicious activity.

Remediation

Immediate Action: Upgrade the Ignition platform to version 8.1.54 or later, or migrate to the unaffected 8.3 version series.

Proactive Monitoring: Review access logs for anomalous project creation events or unauthorized attempts to execute gateway scripts by non-administrative user accounts.

Compensating Controls: If an immediate upgrade is not feasible, manually populate the "Create Project Role(s)" setting in the Gateway configuration to restrict project creation privileges to authorized administrative roles only.

Exploitation status

Public Exploit Available: False

Analyst recommendation

This vulnerability presents a significant risk to the integrity of the Ignition platform by allowing unauthorized project creation. Organizations should treat this as a high priority and proceed with the recommended software updates immediately. If patching is delayed, manual configuration of access control settings is essential to prevent potential exploitation.

Sources

Originally found and disclosed by Christopher Lusk of North Echo Security Research reported this vulnerability to Inductive Automation., Elhussain Fathy (0xSphinx) independently reported this vulnerability and confirmed the fix., per the CVE Program record.