In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.
History

Mon, 07 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 05 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Inductiveautomation
Inductiveautomation ignition
Vendors & Products Inductiveautomation
Inductiveautomation ignition

Fri, 04 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.
Title Inductive Automation Ignition Incorrect Default Permissions
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2026-09-04T21:10:25.580Z

Updated: 2026-09-07T11:17:27.381Z

Reserved: 2026-08-20T19:50:25.107Z

Link: CVE-2026-77393

cve-icon Vulnrichment

Updated: 2026-09-07T11:15:41.924Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T22:17:18.333

Modified: 2026-09-08T15:28:33.090

Link: CVE-2026-77393

cve-icon Redhat

No data.