Authorization Flaw in Ignition Software by Inductive Automation
CVE-2026-77393
8.7HIGH
What is CVE-2026-77393?
In versions 8.1.53 and earlier of Ignition software, a configuration issue caused the 'Create Project Role(s)' setting to be empty. This flaw allowed any authenticated user with gateway script execution privileges to create new projects, bypassing intended access control measures. The subsequent Ignition version 8.1.54 mitigates this issue by enforcing project creation strictly within Designer sessions, ensuring users cannot exploit this vulnerability. The Ignition 8.3 series remains unaffected by this issue.
Affected Version(s)
Ignition 0 <= 8.1.53
Ignition 8.1.54
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Christopher Lusk of North Echo Security Research reported this vulnerability to Inductive Automation.
Elhussain Fathy (0xSphinx) independently reported this vulnerability and confirmed the fix.
