{"id":"CVE-2026-77393","title":"In Ignition 8.1.53 and earlier, the Gateway \"Create Project Role(s)\" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts)","summary":"In Ignition 8.1.53 and earlier, the Gateway \"Create Project Role(s)\" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to De…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-276"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T15:28:33.090","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77393","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd"],"epss":0.00506,"epssPercentile":0.42267,"ingestedAt":"2026-09-07T13:10:57.678Z","slug":"CVE-2026-77393","body":"## Overview\n\nIn Ignition 8.1.53 and earlier, the Gateway \"Create Project Role(s)\" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}