Executive brief
Ignition is an industrial automation and SCADA platform used to monitor and control manufacturing and infrastructure systems. In Ignition 8.1.53 and earlier, a misconfigured default setting allowed any authenticated user with access to gateway scripts to create new projects, bypassing intended authorization controls. This could enable unauthorized users to deploy malicious automation logic or disrupt production environments.
Technical details
The vulnerability is an authorization bypass in the Gateway "Create Project Role(s)" setting, which shipped blank in Ignition 8.1.53 and earlier. This blank configuration allowed any authenticated user to create projects if they could execute gateway scripts, circumventing the intended role-based access control. The attack requires network access to the Ignition gateway and prior authentication; an attacker cannot exploit this unauthenticated. Ignition 8.1.54 remediated the issue by restricting project creation exclusively to Designer sessions and removing reliance on the vulnerable setting. The 8.3 series was not affected by this flaw.
Affected products
- Inductive Automation Ignition 8.1.53 and earlier
Timeline
- 2026-09-04: disclosed
- 8.1.54: patched