Description
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.
Published: 2026-09-04
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from the Ignition Gateway setting "Create Project Role(s)" being shipped blank in versions 8.1.53 and earlier. This default misconfiguration allows any authenticated user who has access to execute gateway scripts to create new projects. Because project creation can trigger arbitrary script execution, an attacker can elevate privileges or execute remote code within the Ignition environment. The weakness corresponds to CWE-276, improper default permissions.

Affected Systems

Inductive Automation Ignition 8.1.53 and all earlier releases are affected. The 8.3 series is not impacted. Users running these versions should apply the vendor fix that populates the "Create Project Role(s)" setting or upgrade to 8.1.54 or any 8.3 release where project creation is restricted to Designer sessions.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity condition. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid credentials and script‑execution rights, but the permissive default makes the attack likely if an attacker gains any authenticated access. The risk remains high until the configuration is corrected or the system is upgraded.

Generated by OpenCVE AI on September 4, 2026 at 22:22 UTC.

Remediation

Vendor Solution

Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the "Create Project Role(s)" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability. Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting "Create Project Role(s)" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings. https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3


OpenCVE Recommended Actions

  • Upgrade Ignition to version 8.1.54 or later (or to the latest 8.3 release).
  • If an upgrade is not immediately possible, populate the "Create Project Role(s)" setting with the Designer role to restrict project creation to that role.
  • Verify that only users with the designated role can create projects and that no unauthorized accounts can execute gateway scripts.

Generated by OpenCVE AI on September 4, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.
Title Inductive Automation Ignition Incorrect Default Permissions
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-04T21:10:25.580Z

Reserved: 2026-08-20T19:50:25.107Z

Link: CVE-2026-77393

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T22:17:18.333

Modified: 2026-09-04T22:17:18.333

Link: CVE-2026-77393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:30:07Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions