PT-2026-85375 · Inductive Automation · Ignition
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ignition versions prior to 8.1.54
Description
An authenticated user can create projects due to a blank default configuration in the Gateway 'Create Project Role(s)' setting. This flaw allows attackers to escalate privileges to project creators and execute gateway scripts, enabling lateral movement across OT (Operational Technology) and IT networks. The issue affects critical infrastructure in the manufacturing, energy, and IT sectors worldwide.
Recommendations
Update to version 8.1.54.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ignition