CVE-2026-77393 affects Inductive Automation Ignition versions 8.1.53 and earlier, where the Gateway 'Create Project Role(s)' setting shipped with a blank default value. This misconfiguration allowed any authenticated user to create projects, provided they had the ability to execute gateway scripts. The vulnerability represents an improper access control issue in the project creation workflow. Ignition version 8.1.54 addresses the issue by restricting project creation exclusively to Designer sessions and removing reliance on the flawed setting. The Ignition 8.3 series is not affected by this vulnerability. CISA has issued an ICS advisory (ICSA-26-246-06) regarding this issue, indicating relevance to operational technology and industrial control system environments. A fix has been made available and users are advised to upgrade to version 8.1.54 or later.