highOther

Inductive Automation Ignition Incorrect Default Permissions Vulnerability (CVE-2026-77393)

First seen Sep 4, 2026 · Updated Sep 4, 2026 · CVSS 8.8

ICSSCADAcritical-infrastructureprivilege-escalationdefault-configurationIgnitionCWE-276

Inductive Automation Ignition versions 8.1.53 and earlier ship with a blank 'Create Project Role(s)' setting, allowing any authenticated user capable of executing gateway scripts to create projects without proper authorization. This default misconfiguration affects widely deployed industrial control system software across Critical Manufacturing, Energy, and IT sectors worldwide, with no known public exploitation reported at this time.

Technical Analysis

CVE-2026-77393 is a CWE-276 (Incorrect Default Permissions) flaw in Inductive Automation Ignition affecting versions up to and including 8.1.53. The vulnerability stems from the Gateway's 'Create Project Role(s)' setting shipping blank by default, meaning the access control mechanism functions correctly but enforces no restriction, permitting any authenticated user who can execute gateway scripts to create projects. The CVSS v3.1 score is 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), reflecting network-exploitable, low-complexity conditions requiring only low privileges. Ignition 8.1.54 remediates this by restricting project creation to Designer sessions rather than relying on the configurable role setting; the 8.3 series is unaffected. This is an OT/ICS platform vulnerability with no direct AI agent system impact, though organizations using Ignition as a data source or control interface for AI-driven industrial automation or agentic monitoring pipelines should ensure proper access controls to prevent unauthorized project manipulation that could feed corrupted data or logic into downstream automated decision systems.

Affected Systems

Inductive Automation Ignition versions 8.1.53 and earlier (Gateway component with default 'Create Project Role(s)' setting left blank). Ignition 8.3 series is not affected; version 8.1.54 and later resolve the issue.

Indicators of Compromise

  • No specific indicators of compromise identified; this is a configuration vulnerability, not an active exploit campaign.

Remediation Steps

  1. 1

    Upgrade Ignition

    Upgrade to Inductive Automation Ignition 8.1.54 or later, or the latest 8.3 version, which restricts project creation to Designer sessions and removes reliance on the vulnerable setting.

  2. 2

    Configure Create Project Role(s)

    For organizations that must remain on an earlier 8.1 version, populate the 'Create Project Role(s)' setting to match the Designer Role via Gateway General Security Settings, ensuring only authorized users can create projects.

  3. 3

    Network Segmentation

    Minimize network exposure of control system devices; ensure Ignition Gateways are not accessible from the internet and are isolated behind firewalls from business networks.

  4. 4

    Secure Remote Access

    When remote access is required, use VPNs or other secure methods, keeping them updated and recognizing their own vulnerabilities.

  5. 5

    Review Gateway Security Settings

    Conduct an audit of all Gateway General Security Settings to identify other default or blank configuration values that could grant unintended permissions.

CVE / Advisory IDs

CVE-2026-77393

Industries Most Exposed

Critical ManufacturingEnergyInformation Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.