SALTO ProAccess Space fixes partition escalation flaw
A privilege escalation bug in SALTO ProAccess Space lets authenticated operators access other partitions' spaces; patched in version 6.13.
CISA has published an advisory for CVE-2026-11889, a privilege escalation vulnerability affecting SALTO ProAccess Space, an access-control management platform used in commercial facilities and critical manufacturing environments worldwide. The flaw stems from CWE-639 (Authorization Bypass Through User-Controlled Key) and allows an authenticated operator to escalate privileges and access spaces outside their assigned partition when the tenancy/logical partitioning feature is enabled. Installations that do not use partitioning are not affected.
Exploitation requires valid operator-level credentials, limiting the attack to insiders or attackers who have already obtained authenticated access. SALTO has released version 6.13 to address the issue, and CISA recommends organizations using the tenancy feature upgrade promptly, apply least-privilege principles to operator accounts, avoid direct internet exposure, and consider isolated Space instances where strong tenant separation is required. The vulnerability was responsibly disclosed by Bernhard Lorenz of Limes Security, and CISA states no known public exploitation has been reported at this time.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free