Unauthenticated API Endpoint Exposure in Inductive Automation Ignition Software
CVE-2025-13913

5.4MEDIUM

Key Information:

Vendor
CVE Published:
12 March 2026

What is CVE-2025-13913?

Inductive Automation's Ignition Software is susceptible to an exposure that allows unauthenticated remote access to an API endpoint. This vulnerability enables attackers to change the 'forgot password' recovery email address, potentially leading to unauthorized access to sensitive accounts. Proper security measures and remediation are essential to protect against such threats.

Affected Version(s)

Ignition Software 0 < 8.3.0

Ignition Software 8.3.0

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta reported this vulnerability to Inductive Automation.
.