Privilege Escalation in SALTO ProAccess Space (CVE‑2026‑11889) Lets Authenticated Users Access All Partitions
What It Is — A CVSS 3.0 6.5 vulnerability (CVE‑2026‑11889) in SALTO ProAccess Space < 6.13 allows an attacker who already possesses valid operator credentials to bypass the tenancy/partition feature and gain unrestricted access to any space managed by the system.
Exploitability — Requires a legitimate, authenticated operator account and the partition feature to be enabled. No public exploit code is known, but the attack path is straightforward once credentials are obtained.
Affected Products — SALTO ProAccess Space versions prior to 6.13 (all deployments that use the tenancy/partition capability).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control (CC6.1) requires documented segregation of duties and evidence that logical partitions are enforced; this flaw shows how a mis‑implemented control can be bypassed.
- SOC 2 Change Management (CC7.1) expects timely remediation of known vulnerabilities; the need to patch to 6.13 provides a concrete audit artifact.
- Continuous control monitoring can surface un‑patched versions before an attacker leverages them, delivering defensible evidence for auditors and enterprise buyers.
Recommended Actions
- Upgrade all SALTO ProAccess Space installations to version 6.13 or later.
- If the tenancy feature is not required, disable partitioning to eliminate the attack surface.
- Review and tighten access‑control policies around operator credentials; enforce MFA where possible.
- Capture patch‑deployment logs and partition‑configuration snapshots as SOC 2 audit evidence.
Source: CISA Advisory – ICSA‑26‑197‑07