CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

SALTO ProAccess Space

criticalCVE-2026-11889
View CSAF Summary Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected. The following versions of SALTO ProAccess Space are affected: ProAccess Space <6.13 (CVE-2026-11889) CVSS Vendor Equipment Vulnerabilities v3 6.5 SALTO SALTO ProAccess Space Authorization Bypass Through User-Controlled Key Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Spain Vulnerabilities Expand All + CVE-2026-11889 SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product. View CVE Details Affected Products SALTO ProAccess Space Vendor: SALTO Product Version: SALTO ProAccess Space: <6.13 Product Status: known_affected Remediations Mitigation Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13. Vendor fix To further enhance security after applying the update: 1. Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet. 2. Restrict operator-level accounts to the minimum required and apply least-privilege principles. 3. If feasible, disable the partitioning feature and operate under a single partition. 4. When strong tenant separation is required, consider running separate Space instances (isolated environments) rather than relying solely on logical partitioning. Relevant CWE: CWE-639 Authorization Bypass Through User-Controlled Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:

CSIRTS triage

What
Authenticated attackers can escalate privileges and access unauthorized spaces.
Who is affected
Authenticated users of SALTO ProAccess Space installations with partitioning enabled.
Urgency
Remediation is critical due to the potential for unauthorized access.
Action
Users should upgrade to version 6.13 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch ProAccess Space

Get an email when a new ProAccess Space advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-07-16
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-11889coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for SALTO ProAccess Space

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories