Description
Inductive Automation Ignition Software is vulnerable to an unauthenticated API endpoint exposure that may allow an attacker to remotely change the "forgot password" recovery email address.
Problem types
Product status
Any version before 8.3.0
8.3.0
Credits
Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta reported this vulnerability to Inductive Automation.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-071-06
github.com/...p/csaf_files/OT/white/2026/icsa-26-071-06.json
inductiveautomation.com/...ignition-security-hardening-guide