Critical Vulnerability in Inductive Automation Ignition Allows Unauthorized Project Creation
CVE-2026-77393 affects Ignition versions 8.1.53 and earlier due to blank default permission setting
Key Takeaways
- CVE-2026-77393 affects Inductive Automation Ignition versions 8.1.53 and earlier due to a blank default in the "Create Project Role(s)" setting.
- Exploitation requires attacker authentication and the ability to execute gateway scripts, but the blank default permits unrestricted project creation.
- Inductive Automation Ignition 8.1.54 and later, as well as the 8.3 series, are not affected by this vulnerability.
- Users on unaffected versions should ensure the "Create Project Role(s)" setting is properly configured as a defense-in-depth measure.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


