CVE-2025-13911

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
28/08/2026

Description

Ignition by Inductive Automation, when installed with default OS service<br /> account settings, may expose the host system to an elevated code <br /> execution risk via the gateway backup restore functionality. An <br /> authenticated user with Gateway Administrator privileges can import a <br /> malicious gateway backup (.gwbk) file containing crafted project <br /> resources, scripts, or modules, resulting in code execution on the host <br /> system. This affects both Windows and Linux installations. On Windows, <br /> default installations often run the Ignition service as NT <br /> AUTHORITY\SYSTEM, resulting in code execution with full local system <br /> privileges. On Linux, default installations commonly run the Ignition <br /> service as root or with elevated privileges. Specific privilege level <br /> depends on installation configuration.