Privilege Escalation Vulnerability in SALTO ProAccess Space

Learn how the CVE-2026-11889 vulnerability in SALTO ProAccess Space enables privilege escalation and how to mitigate it. Update now!

viernes, 17 de julio de 2026 • 5 min read • Q2BSTUDIO Team

Critical Patch: Privilege Escalation in ProAccess Space

A privilege escalation vulnerability has recently been identified in the SALTO ProAccess Space access control system, which affects installations that use the logical partitioning (tenancy) functionality. This flaw, cataloged as CVE-2026-11889, allows an authenticated attacker to access spaces outside of their assigned partition, compromising data separation and facility security. While physical access and elevated privileges are not required, you do need valid operator credentials and partitioning enabled. Versions prior to 6.13 are the only ones affected, and unpartitioned organizations are not at risk. However, given the criticality of the sector — critical infrastructure such as commercial facilities and manufacturing — repair should be a priority.

The attack vector is remote, with low complexity and no user interaction. The CVSS 3.1 metric assigns a base score of 6.5 (MEDIUM) due to the high impact on integrity, although it does not affect availability or direct confidentiality. In CVSS 4.0 the severity rises to 7.1 (HIGH). The vulnerability is classified as CWE-639, i.e., bypass of authorization by user-controlled key. This means that a legitimate operator can manipulate parameters or partition identifiers to bypass restrictions and access doors, zones, or data of other customers within the same shared system.

From a technical standpoint, the flaw lies in how the application validates a user's membership in a partition. By failing to properly verify the partition key in certain operations, an attacker can modify HTTP requests or internal parameters to trick the server. In environments where a single ProAccess Space deployment hosts multiple organizations (e.g., corporate buildings, shopping malls, or university campuses), this gap could allow restricted doors to be opened or third-party security configurations modified. The original report from Limes Security, which reported the vulnerability to CISA, highlights that the exploit is viable even with a low-privilege carrier account.

The official solution is to update to version 6.13, which fixes partition key validation. In addition, SALTO recommends additional measures: operating the software on a protected internal network, without direct exposure to the Internet; apply the principle of least privilege in operator accounts; if possible, disable the partitioning feature and operate on a single partition; and, when strong separation between tenants is required, consider running separate instances of Space (sandboxed environments) rather than relying only on logical partitioning. These practices are consistent with CISA's industrial cybersecurity guidelines, which insist on network segmentation and the use of VPNs for remote access.

Beyond the patch, this vulnerability highlights a recurring problem in physical access control systems: excessive reliance on application logic to segregate sensitive data. Access management software solutions are often deployed in converged environments where IT security and physical security are intertwined. Any failure in authentication or authorization can have tangible consequences: from the loss of confidentiality in entry records to the possibility of unauthorized people accessing restricted areas. Therefore, organizations must treat these systems with the same rigor as any other business-critical application.

In this context, cybersecurity is not just an add-on, but a fundamental pillar in the design and operation of any technological platform. At Q2BSTUDIO we offer cybersecurity and pentesting services that allow us to assess the security posture of systems such as ProAccess Space, identifying vulnerabilities before they are exploited. Our team performs custom audits, penetration testing, and configuration analysis to ensure that the protection measures implemented are effective. In addition, we accompany companies in migrating to secure versions and defining robust access policies.

The vulnerability described also underscores the importance of developing custom applications with built-in security controls from the design phase. At Q2BSTUDIO, we create custom software that incorporates secure by design principles, using modern frameworks and code review practices. Our approach includes implementing multi-factor authentication, role-based access control, and comprehensive input validation to prevent attacks such as authorization bypass. As these are customized solutions, we can adapt the partitioning logic to the real needs of each client, avoiding generic configurations that are often a source of failures.

On the other hand, the cloud offers alternatives to improve security. AWS and Azure cloud services enable you to deploy isolated environments with virtual networks, security groups, and fine-grained IAM policies. At Q2BSTUDIO we offer AWS and Azure cloud services that include the migration, configuration and management of secure infrastructures. For example, a dedicated VM can be instantiated for each ProAccess Space tenant, completely eliminating the need for logical partitioning. Combined with the use of artificial intelligence for the detection of anomalies in access logs, a much more resilient system is obtained. Our AI agents can monitor usage patterns and alert on suspicious behavior, such as unauthorized partition access attempts.

Artificial intelligence for companies is not only used for security, but also for optimizing operations. For example, by integrating Power BI with ProAccess Space logs, dashboards can be created that visualize space occupancy, access frequency, or peak hours. These business intelligence services help make informed decisions about resource allocation and facilities management. At Q2BSTUDIO we develop custom dashboards that connect data from physical systems with analysis tools, all under the highest security standards.

In addition, automating processes using custom applications can reduce the attack surface. For example, an automated flow that reassigns operator credentials at the end of a shift, or locks inactive accounts after a period of no use. These actions, previously manual, can now be managed by AI agents that execute predefined policies. The combination of custom software, artificial intelligence, and AWS/Azure cloud services forms an ecosystem where security is proactive, not reactive.

In summary, the CVE-2026-11889 vulnerability in SALTO ProAccess Space is a reminder that no system is without its flaws, especially those that manage physical security using software logic. Upgrading to version 6.13 is urgent, but true long-term protection comes from a comprehensive approach: regular cybersecurity assessments, custom application development with robust controls, deployment in secure cloud infrastructures, and the use of business intelligence to maintain visibility. At Q2BSTUDIO, we are prepared to accompany organizations on each of these fronts, offering technological solutions ranging from pentesting to the implementation of AI agents, all under the same umbrella of excellence and trust.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.