Impact
The vulnerability originates from the Ignition Gateway setting "Create Project Role(s)" being shipped blank in versions 8.1.53 and earlier. This default misconfiguration allows any authenticated user who has access to execute gateway scripts to create new projects. Because project creation can trigger arbitrary script execution, an attacker can elevate privileges or execute remote code within the Ignition environment. The weakness corresponds to CWE-276, improper default permissions.
Affected Systems
Inductive Automation Ignition 8.1.53 and all earlier releases are affected. The 8.3 series is not impacted. Users running these versions should apply the vendor fix that populates the "Create Project Role(s)" setting or upgrade to 8.1.54 or any 8.3 release where project creation is restricted to Designer sessions.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity condition. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid credentials and script‑execution rights, but the permissive default makes the attack likely if an attacker gains any authenticated access. The risk remains high until the configuration is corrected or the system is upgraded.
OpenCVE Enrichment