CVE-2026-77393CWE-276

CVE-2026-77393

High · published September 5, 2026

CVSS v3.1
8.8
EPSS
1%
Percentile
41.3
In the wild
Unconfirmed
What it is

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00506 · 41.3th percentile
Weakness
CWE-276 · Incorrect Default Permissions
Published
2026-09-05T02:17Z
References (3)
EPSS history
Timeline
  • 06 SEP 03:33Z
    EPSS moved — → 1%
    epss
  • 04 SEP 21:10Z
    Inductive Automation Ignition Incorrect Default Permissions
    cvelistv5