Description
A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.
Problem types
Product status
Any version before 8.3.0
8.3.0
Credits
Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta reported this vulnerability to Inductive Automation.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-071-06
github.com/...p/csaf_files/OT/white/2026/icsa-26-071-06.json
inductiveautomation.com/...ignition-security-hardening-guide