Our takeCISA advisory ICSA-26-246-06 flags CVE-2026-77393 in Inductive Automation Ignition <=8.1.53: incorrect default permissions let any authenticated user create projects (CVSS 8.8). Ignition runs small plants as well as big ones — update if it sits in your OT stack.Cyber Resilience desk
What this means for you — Security leader:Update Ignition to >8.1.53 if you self-host it; the incorrect default permissions (CVSS 8.8) let any authenticated user create projects.
What this means for you — Lean IT orgs:If you run Ignition on-prem, update it past 8.1.53 as soon as you can; the flaw lets any logged-in user create projects.
What this means for you — MSP:Check every client running self-hosted Ignition and update past 8.1.53; the incorrect default permissions let any authenticated user create projects.
What this means for you — Researcher:CISA advisory ICSA-26-246-06 flags CVE-2026-77393 in Inductive Automation Ignition <=8.1.53: incorrect default permissions let any authenticated user create projects (CVSS 8.8). Ignition runs small plants as well as big ones — update if it sits in your OT stack.