THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-77393 (HIGH 8.8) — In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on thi

[NVD] CVE-2026-77393 (HIGH 8.8) — In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on thi

mednvdPublished 2026-09-04

CVE-2026-77393 CVSS: 8.8 HIGH Published: 2026-09-04T22:17:18.333

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77393