SALTO ProAccess Space
View CSAF Summary Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected. The following versions of SALTO ProAccess Space are affected: ProAccess Space <6.13 (CVE-2026-11889) CVSS Vendor Equipment Vulnerabilities v3 6.5 SALTO SALTO ProAccess Space Authorization Bypass Through User-Controlled Key Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Spain Vulnerabilities Expand All + CVE-2026-11889 SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product. View CVE Details Affected Products SALTO ProAccess Space Vendor: SALTO Product Version: SALTO ProAccess Space: <6.13 Product Status: known_affected Remediations Mitigation Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13. Vendor fix To further enhance security after applying the update: 1. Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet. 2. Restrict operator-level accounts to the minimum required and apply least-privilege principles. 3. If feasible, disable the partitioning feature and operate under a single partition. 4. When strong tenant separation is required, consider running separate Space instances (isolated environments) rather than relying solely on logical partitioning. Relevant CWE: CWE-639 Authorization Bypass Through User-Controlled Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:
CSIRTS triage
- What
- Authenticated attackers can escalate privileges and access unauthorized spaces.
- Who is affected
- Authenticated users of SALTO ProAccess Space installations with partitioning enabled.
- Urgency
- Remediation is critical due to the potential for unauthorized access.
- Action
- Users should upgrade to version 6.13 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ProAccess Space
Get an email when a new ProAccess Space advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-118890.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-11889 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for SALTO ProAccess Space
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- criticalSchneider Electric IGSS2026-07-30
- criticalOpen Source Software: Security Principles and Practices2026-07-30
- criticalMikroTik RouterOS2026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30