HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Privilege Escalation in SALTO ProAccess Space (CVE‑2026‑11889) Lets Authenticated Users Access All Partitions

A CVSS 6.5 vulnerability in SALTO ProAccess Space < 6.13 allows an attacker with valid operator credentials to bypass tenancy partitions and gain unrestricted access to all managed spaces. For SOC 2‑compliant organizations, this highlights the need for continuous access‑control monitoring and timely patch evidence.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Privilege Escalation in SALTO ProAccess Space (CVE‑2026‑11889) Lets Authenticated Users Access All Partitions

What It Is — A CVSS 3.0 6.5 vulnerability (CVE‑2026‑11889) in SALTO ProAccess Space < 6.13 allows an attacker who already possesses valid operator credentials to bypass the tenancy/partition feature and gain unrestricted access to any space managed by the system.

Exploitability — Requires a legitimate, authenticated operator account and the partition feature to be enabled. No public exploit code is known, but the attack path is straightforward once credentials are obtained.

Affected Products — SALTO ProAccess Space versions prior to 6.13 (all deployments that use the tenancy/partition capability).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Control (CC6.1) requires documented segregation of duties and evidence that logical partitions are enforced; this flaw shows how a mis‑implemented control can be bypassed.
  • SOC 2 Change Management (CC7.1) expects timely remediation of known vulnerabilities; the need to patch to 6.13 provides a concrete audit artifact.
  • Continuous control monitoring can surface un‑patched versions before an attacker leverages them, delivering defensible evidence for auditors and enterprise buyers.

Recommended Actions

  • Upgrade all SALTO ProAccess Space installations to version 6.13 or later.
  • If the tenancy feature is not required, disable partitioning to eliminate the attack surface.
  • Review and tighten access‑control policies around operator credentials; enforce MFA where possible.
  • Capture patch‑deployment logs and partition‑configuration snapshots as SOC 2 audit evidence.

Source: CISA Advisory – ICSA‑26‑197‑07

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-07

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →