In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the "Create Project Role(s)" setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability. Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting "Create Project Role(s)" to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings. https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3


Workaround

No workaround given by the vendor.

History

Fri, 04 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.
Title Inductive Automation Ignition Incorrect Default Permissions
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-04T21:10:25.580Z

Reserved: 2026-08-20T19:50:25.107Z

Link: CVE-2026-77393

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses