Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the "Create Project Role(s)" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability. Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting "Create Project Role(s)" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings. https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected. | |
| Title | Inductive Automation Ignition Incorrect Default Permissions | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-04T21:10:25.580Z
Reserved: 2026-08-20T19:50:25.107Z
Link: CVE-2026-77393
No data.
Status : Received
Published: 2026-09-04T22:17:18.333
Modified: 2026-09-04T22:17:18.333
Link: CVE-2026-77393
No data.
OpenCVE Enrichment
Updated: 2026-09-04T22:30:07Z