As cited
Copy frozen at (site build).
vulnerabilities
SALTO ProAccess Space
SALTO ProAccess Space versions before 6.13 contain a privilege escalation vulnerability (CVE-2026-11889) that allows authenticated attackers to bypass authorization and access spaces outside their assigned partition when the tenancy feature is enabled. The vulnerability has a CVSS score of 6.5 and affects physical access control systems deployed worldwide. SALTO recommends upgrading to version 6.13 and implementing additional security measures including network isolation and least-privilege access controls.
Why it matters: Organizations operating SALTO ProAccess Space with logical partitioning should prioritize upgrading to version 6.13, as authenticated insiders or compromised operator accounts can escalate privileges to access restricted areas across physical security installations.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
SALTO ProAccess Space
SALTO ProAccess Space versions before 6.13 contain CVE-2026-11889, a privilege escalation vulnerability that allows authenticated attackers to bypass authorization and access spaces outside their assigned partition when the tenancy feature is enabled. The vulnerability requires valid operator credentials and does not affect installations without partitioning. SALTO recommends upgrading to version 6.13 and implementing network isolation, least-privilege access controls, and consideration of separate instances for strong tenant separation.
Why it matters: Organizations operating SALTO ProAccess Space with partitioning enabled in critical infrastructure (commercial facilities, critical manufacturing) worldwide should upgrade to 6.13 immediately to prevent authorized insiders from accessing unauthorized areas.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
SALTO ProAccess Space
SALTO ProAccess Space versions before 6.13 contain CVE-2026-11889, a privilege escalation vulnerability that allows authenticated attackers to bypass authorization and access spaces outside their assigned partition when the tenancy feature is enabled. The vulnerability requires valid operator credentials and does not affect installations without partitioning. SALTO recommends upgrading to version 6.13 and implementing network isolation, least-privilege access controls, and consideration of separate instances for strong tenant separation.
Why it matters: Organizations operating SALTO ProAccess Space with partitioning enabled in critical infrastructure (commercial facilities, critical manufacturing) worldwide should upgrade to 6.13 immediately to prevent authorized insiders from accessing unauthorized areas.
- Source published
- First seen by Cybersecurity Tracker