PT-2026-85375 · Inductive Automation · Ignition

·

CVE-2026-77393

·

Published

2026-09-03

·

Updated

2026-09-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ignition versions prior to 8.1.54
Description An authenticated user can create projects due to a blank default configuration in the Gateway 'Create Project Role(s)' setting. This flaw allows attackers to escalate privileges to project creators and execute gateway scripts, enabling lateral movement across OT (Operational Technology) and IT networks. The issue affects critical infrastructure in the manufacturing, energy, and IT sectors worldwide.
Recommendations Update to version 8.1.54.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77393

Affected Products

Ignition