news.mlab.sh
Back to the feed
vulnerability

SALTO ProAccess Space

Critical
Summary

A critical vulnerability (CVE-2026-11889) exists in SALTO ProAccess Space versions prior to 6.13, allowing an authenticated attacker to escalate privileges and gain unauthorized access to spaces beyond their assigned partition. Exploitation requires valid operator credentials and partitioning to be enabled. This affects commercial facilities and critical manufacturing sectors worldwide.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding a critical vulnerability in SALTO ProAccess Space software. Versions prior to 6.13 are susceptible to a privilege escalation attack, potentially enabling an attacker with valid operator credentials to access spaces outside their designated partition within the same SALTO ProAccess Space installation. This vulnerability is linked to the tenancy feature, which utilizes logical partitioning. Installations without partitioning are not affected. The advisory highlights that this vulnerability affects commercial facilities and critical manufacturing sectors globally, with the vulnerability being present worldwide. CISA recommends that users of SALTO ProAccess Space utilizing the tenancy feature upgrade to version 6.13 immediately. Additional mitigation steps include operating ProAccess Space on a protected internal network, restricting operator-level accounts, disabling partitioning if feasible, and running separate Space instances for tenant separation when strong isolation is needed. The advisory emphasizes minimizing network exposure for control system devices and isolating them from business networks, along with utilizing secure remote access methods like VPNs, recognizing that VPNs themselves can have vulnerabilities. CISA encourages organizations to perform impact analysis and risk assessments and to implement recommended cybersecurity strategies for proactive defense of ICS assets. No public exploitation specifically targeting this vulnerability has been reported at the time of this advisory.

Read the full article at CISA Advisories