SALTO ProAccess Space Privilege Escalation via Authorization Bypass (CVE-2026-11889)
First seen Jul 17, 2026 · Updated Jul 17, 2026 · CVSS 6.5
A privilege escalation vulnerability exists in SALTO ProAccess Space access control software versions prior to 6.13, affecting installations using the tenancy/logical partition feature. An authenticated attacker with valid operator credentials can bypass partition boundaries to access spaces outside their assigned tenancy, potentially compromising physical access control across an organization's facilities.
Technical Analysis
CVE-2026-11889 is an Authorization Bypass Through User-Controlled Key (CWE-639) affecting SALTO ProAccess Space versions below 6.13 when the tenancy/partition feature is enabled. The flaw allows an authenticated operator to manipulate a user-controlled key to escalate privileges and access spaces or partitions outside their authorized scope within the same installation. Exploitation requires valid operator credentials and does not require user interaction, with CVSS v3.1 scoring 6.5 (Medium) and CVSS v4.0 scoring 7.1 (High) due to network-based attack vector and low attack complexity. This is a physical access control system vulnerability with no direct AI agent system impact, as it pertains to building/facility access management rather than IT infrastructure, credentials, or software supply chains relevant to LLM or agent pipelines.
Affected Systems
SALTO ProAccess Space versions prior to 6.13, specifically installations with the tenancy feature/logical partitioning enabled. Installations without partitioning enabled are not affected.
Indicators of Compromise
- No known IOCs; no public exploitation reported at time of advisory publication.
Remediation Steps
- 1
Upgrade software
Upgrade SALTO ProAccess Space to version 6.13 or later, especially if using the tenancy/partition feature.
- 2
Network isolation
Operate ProAccess Space on a protected internal network; avoid direct internet exposure.
- 3
Restrict operator accounts
Limit operator-level accounts to the minimum necessary and enforce least-privilege access principles.
- 4
Disable partitioning if not needed
If feasible, disable the partitioning feature and operate under a single partition to eliminate the attack surface.
- 5
Use isolated instances for strong tenant separation
For environments requiring strong tenant isolation, deploy separate Space instances rather than relying solely on logical partitioning.
- 6
Secure remote access
Use VPNs for remote access needs and keep them updated; place control system networks behind firewalls separate from business networks.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.