Inductive Automation recommends upgrading to Ignition 8.1.54 or later, or the latest 8.3 version, which restricts project creation to Designer sessions and no longer relies on the "Create Project Role(s)" setting. Users on earlier 8.1 versions should populate the "Create Project Role(s)" setting to match their Designer Role, restricting project creation to authorized users only. CISA also recommends minimizing network exposure, placing control system devices behind firewalls, and using VPNs for remote access.
Quick answers
What is CVE-2026-77393?
Inductive Automation recommends upgrading to Ignition 8.1.54 or later, or the latest 8.3 version, which restricts project creation to Designer sessions and no longer relies on the "Create Project Role(s)" setting. Users on earlier 8.1 versions should populate the "Create Project Role(s)" setting to match their Designer Role, restricting project creation to authorized users only. CISA also recommends minimizing network exposure, placing control system devices behind firewalls, and using VPNs for remote access.
How severe is CVE-2026-77393?
high, CVSS 8.8
Is CVE-2026-77393 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-77393 be mitigated?
Inductive Automation recommends upgrading to Ignition 8.1.54 or later, or the latest 8.3 version, which restricts project creation to Designer sessions and no longer relies on the "Create Project Role(s)" setting. Users on earlier 8.1 versions should populate the "Create Project Role(s)" setting to match their Designer Role, restricting project creation to authorized users only. CISA also recommends minimizing network exposure, placing control system devices behind firewalls, and using VPNs for remote access.
CVSS
8.8
Vendor
Inductive Automation
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Inductive Automation Ignition
Mitigation
Inductive Automation recommends upgrading to Ignition 8.1.54 or later, or the latest 8.3 version, which restricts project creation to Designer sessions and no longer relies on the "Create Project Role(s)" setting. Users on earlier 8.1 versions should populate the "Create Project Role(s)" setting to match their Designer Role, restricting project creation to authorized users only. CISA also recommends minimizing network exposure, placing control system devices behind firewalls, and using VPNs for remote access.
A critical vulnerability in Inductive Automation Ignition Gateway, tracked as CVE-2026-77393, stems from an incorrect default permission where the "Create Project Role(s)" setting shipped blank. This allowed any authenticated user capable of executing gateway scripts to create projects without restriction. The issue affects versions 8.1.53 and earlier; version 8.1.54 and later, as well as the 8.3 series, are not affected. The vulnerability has been reported by two independent researchers and carries a CVSS v3 base score of 8.8 (HIGH).