---
id: CVE-2026-77393
title: >-
  In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting
  shipped blank, which permitted any authenticated user to create projects (if
  they can execute gateway scripts)
summary: >-
  In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting
  shipped blank, which permitted any authenticated user to create projects (if
  they can execute gateway scripts). Ignition 8.1.54 restricts project creation
  to De…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-276
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T15:28:33.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77393'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00506
epssPercentile: 0.40593
ingestedAt: '2026-09-07T13:10:57.678Z'
---

## Overview

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
