VYPR
advisoryPublished Sep 3, 2026· 1 source

CISA Flags Critical Default Permission Flaw in Inductive Automation Ignition

A critical vulnerability in Inductive Automation's Ignition platform, CVE-2026-77393, allows any authenticated user to create projects due to insecure default permissions.

CISA has issued an advisory detailing a critical vulnerability, CVE-2026-77393, affecting Inductive Automation's widely used Ignition industrial control system software. The flaw, present in versions 8.1.53 and earlier, stems from incorrect default permissions that allow any authenticated user to create new projects within the system.

The vulnerability arises because the Gateway "Create Project Role(s)" setting in affected versions was left blank by default. This configuration meant that no specific role was required to create projects, provided the user could execute gateway scripts. Exploitation of this weakness could lead to unauthorized project creation, potentially disrupting operations or enabling further malicious activity within an industrial environment.

The CVSS score for this vulnerability is rated as HIGH, with a base score of 8.8 for CVSS v3.1 and 8.7 for CVSS v4.0. The metrics indicate a significant risk, with potential for high impact on confidentiality, integrity, and availability (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Inductive Automation has clarified that this is a configuration issue rather than a flaw in the core access control logic. The security control correctly enforced the blank setting. To remediate the vulnerability, users are strongly advised to upgrade to Ignition version 8.1.54 or later, or any version within the 8.3 series, which restricts project creation to Designer sessions and no longer relies on the problematic setting.

For organizations unable to upgrade immediately, a mitigation is available. Users can manually populate the "Create Project Role(s)" setting within their Ignition Gateway's General Security Settings. By assigning a specific role to this setting, only users possessing that role will be able to create new projects, effectively closing the vulnerability.

This advisory impacts critical infrastructure sectors including Critical Manufacturing and Energy, with deployments reported worldwide. The United States-based company's software is a key component in many industrial operations, making timely patching and mitigation crucial.

While no public exploitation of this specific vulnerability has been reported to CISA at this time, the potential for widespread impact necessitates prompt action. CISA recommends general defensive measures for all control system devices, including minimizing network exposure, isolating control system networks behind firewalls, and using secure remote access methods like VPNs.

The vulnerability was independently reported by Christopher Lusk of North Echo Security Research and Elhussain Fathy (0xSphinx), who also confirmed the fix. CISA encourages organizations to follow established procedures for reporting suspected malicious activity and to implement recommended cybersecurity strategies for proactive defense of Industrial Control Systems (ICS) assets.

Synthesized by Vypr AI