Inductive Automation Ignition

Plan PatchCVSS 8.8ICS-CERT ICSA-26-246-06Sep 3, 2026
Inductive Automation
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Any authenticated user can create projects in Ignition because the default "Create Project Role(s)" setting is blank. This allows users without authorization to create, modify, or inject malicious logic into projects that control plant operations. The vulnerability exists in Ignition versions 8.1.53 and earlier. Inductive Automation reports this is a configuration issue, not an access control flaw. Users on 8.1.54 or later have project creation restricted to Designer sessions. Earlier versions can be remediated by populating the "Create Project Role(s)" setting to restrict access to a specific Designer Role.

What this means
What could happen
Any user with access to the Ignition gateway can create new projects without authorization, potentially allowing unauthorized modifications to control logic, data flows, or HMI screens that direct plant operations.
Who's at risk
Water authorities and electric utilities using Ignition as their HMI/SCADA platform. Affects any site running Ignition 8.1.53 or earlier where the project creation role setting has not been manually configured. Engineers and plant operators who rely on Ignition for process control visibility and setpoint management are at risk if unauthorized users create or modify projects.
How it could be exploited
An attacker with network access to the Ignition gateway and valid login credentials (any user account) can navigate to the project creation function and create a new project. Because the default "Create Project Role(s)" setting is blank, no additional role check is performed. The attacker can then modify or inject malicious logic into the created project to alter control setpoints, disable safety interlocks, or disrupt the HMI interface.
Prerequisites
  • Network access to the Ignition gateway web interface (typically port 8088 or custom port)
  • Valid user credentials for any account on the Ignition gateway
  • Ignition version 8.1.53 or earlier
Remotely exploitableLow complexityValid credentials required but default misconfiguration allows any authenticated user
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (1)
ProductAffected VersionsFix Status
Ignition≤ 8.1.53No fix yet
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDIf upgrading is not immediately possible, set the 'Create Project Role(s)' field in Gateway General Security Settings to your Designer Role to restrict project creation to authorized users only
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpgrade Ignition to version 8.1.54 or later, or switch to the latest 8.3 version
Long-term hardening
0/1
HARDENINGRestrict network access to the Ignition gateway web interface to authorized engineering and operator networks using firewall rules
API: /api/v1/advisories/19aec30a-6e63-4dce-a669-829cec7dc335

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Inductive Automation Ignition | CVSS 8.8 - OTPulse