Inductive Automation · Ignition · CVE-2026-77393
**Name of the Vulnerable Software and Affected Versions**
Ignition versions prior to 8.1.54
**Description**
An authenticated user can create projects due to a blank default configuration in the Gateway 'Create Project Role(s)' setting. This flaw allows attackers to escalate privileges to project creators and execute gateway scripts, enabling lateral movement across OT (Operational Technology) and IT networks. The issue affects critical infrastructure in the manufacturing, energy, and IT sectors worldwide.
**Recommendations**
Update to version 8.1.54.