Security1 distinct publisher3 min readPublished
CVE-2026-77393 asks only for an authenticated account that can run gateway scripts. Inductive Automation calls it a default-value problem. Sites staying on 8.1 close it by populating one role field.
The Watch · Security desk

security
Rockwell's redundancy config tool loads a standard user's DLL as SYSTEM1 distinct publisher
security
A weak bcrypt setting turns every unencrypted OTTO Fleet Manager backup into a credential file1 distinct publisher
security
CISA advisory covers 2021 Logix denial-of-service flaw across ControlLogix, GuardLogix and CompactLogix lines1 distinct publisher
build
One Gitea Signup Now Buys Shell Access. Patch, Close Registration, Audit Hooks Before August 28.1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
The precondition carries the whole finding. An attacker needs an authenticated account plus the ability to execute gateway scripts [2]. On most gateways that is not the full user population, but it is a wider set than the Designer role holders an operator would assume were the only people able to stand up a project [6]. The exposure lives in the gap between those two groups.
Inductive Automation frames it as a default-value problem: the security control enforced exactly what the "Create Project Role(s)" setting specified, and because the setting shipped blank, no role was required [5]. CISA files it as CWE-276, incorrect default permissions [7]. It is a permissions-default flaw rather than a code-level one, the setting shipped open, and reachability depends entirely on who has script execution.
There are two remediation paths, and they carry different operational costs. Upgrading to 8.1.54 restricts project creation to Designer sessions and removes the setting from the decision [3]. Remaining on an earlier 8.1 build and populating the field to match your Designer Role also fully closes it, by the vendor's account, after which only holders of that role can create projects [6][5]. For a gateway behind a change window that is weeks out, the second path is a text field rather than a service restart.
The version arithmetic is unusually friendly. 8.1.53 to 8.1.54 is a single patch increment inside the same branch, and the 8.3 series was never affected, so nobody is being asked to migrate a major version to get the fix [13].
Determining whether you were ever exposed means reading a config value, not a version string. An operator who populated "Create Project Role(s)" when the gateway was commissioned held the same 8.1.53 build and had no exposure at all [5]. That is why fleet-level answers are slow here: the affected population is defined by which sites filled in a field, across critical manufacturing, energy and IT deployments worldwide [8].
Two researchers arrived at it independently. Christopher Lusk of North Echo Security Research reported it to the vendor, and Elhussain Fathy (0xSphinx) reported it separately and confirmed the fix [9][10][14]. CISA states there is no known public exploitation specifically targeting the flaw [11], and its advisory attaches the standard ICS mitigation block about keeping control systems off the internet and behind firewalls [12]. That guidance is sound in general and irrelevant to this bug, because the attacker in this model already has credentials.
Defaults that mean "allow" keep producing advisories of this shape. They do not surface in a dependency scan or a code review. They surface in a config export, which is the artefact fewest OT teams diff between releases.
Ranked by verification strength, evidence, and original report placement.
CISA's ICS advisory on Inductive Automation Ignition covers CVE-2026-77393, affecting Ignition versions 8.1.53 and earlier.
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects if they could execute gateway scripts.
Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on the "Create Project Role(s)" setting.
Inductive Automation determined the issue is a default-value configuration rather than a flaw in the access control itself: the security control enforces exactly what the "Create Project Role(s)" setting specifies, and because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability.
Users who must remain on an earlier 8.1 version can fully remediate by setting "Create Project Role(s)" to match their Designer Role; once populated, only users holding that role can create projects.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise, but single-sourced
The specifics are unusually clean for an ICS bug: an exact affected ceiling at 8.1.53, a named fix release, an unaffected branch, a CWE class, and two researchers who found the same blank field independently. All of it arrives through one document, with the vendor's own mitigation text quoted inside it, and the severity block is empty — nobody outside that pairing has reproduced or scored the finding.
Fix shipped, exposure uncounted
What we can observe is supply-side: a patched build exists, a configuration workaround exists, and the vendor documents both. The demand side is blank. 'Worldwide' across three critical sectors is a category, not a count, and there is no telemetry, scan data or customer statement telling anyone how many gateways still sit on 8.1.53 with an empty role field.
Understated by the vendor's framing
Nothing here is oversold. If the balance tips, it tips the other way: 'a default-value configuration, not a flaw in the access control' is accurate as far as it goes — the control obeyed an empty list — and it also lets fifty-three releases' worth of shipped-blank permission read as a settings nit. Two researchers stumbling onto the same field independently suggests it was not hard to see.
Vendor language inside the advisory
Read who benefits from which sentence. Inductive Automation gains from the default-value classification and from the line that populating one field is full remediation; CISA's interest is in getting an actionable notice out; the two named researchers gain the credit that coordinated disclosure pays in. None of these pressures is hidden, but the vendor's framing is printed as the advisory's own mitigation guidance rather than as an attributed position.
Authoritative issuer, no second look
We would act on this: it is the agency ICS teams treat as the record, the version claims are falsifiable, and the remediation is testable in an afternoon. Confidence stops short of high because a single issuer, an empty metrics block and no external reproduction leave the impact side of the story resting entirely on the vendor's characterisation.