Authorization Flaw in Ignition Software by Inductive Automation
CVE-2026-77393

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-77393?

In versions 8.1.53 and earlier of Ignition software, a configuration issue caused the 'Create Project Role(s)' setting to be empty. This flaw allowed any authenticated user with gateway script execution privileges to create new projects, bypassing intended access control measures. The subsequent Ignition version 8.1.54 mitigates this issue by enforcing project creation strictly within Designer sessions, ensuring users cannot exploit this vulnerability. The Ignition 8.3 series remains unaffected by this issue.

Affected Version(s)

Ignition 0 <= 8.1.53

Ignition 8.1.54

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christopher Lusk of North Echo Security Research reported this vulnerability to Inductive Automation.
Elhussain Fathy (0xSphinx) independently reported this vulnerability and confirmed the fix.
.