Description
SALTO ProAccess Space software using the tenancy feature / logical
partition is vulnerable to a privilege escalation attack that could
allow an authorized attacker to access any space managed by the affected
product.
Published: 2026-07-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Salto ProAccess Space uses a tenancy or logical partitioning feature that, when misconfigured or improperly implemented, can allow an authenticated user to bypass intended access controls and access spaces managed by the product. The vulnerability, identified as CWE‑639, can lead to unauthorized reading or modification of assets in partitions other than the one assigned to the attacker.

Affected Systems

All installations of SALTO ProAccess Space that employ the tenancy or logical partitioning functionality, especially those running versions prior to 6.13. Users who have not upgraded to 6.13 must consider their deployment exposed to this authorization bypass.

Risk and Exploitability

The flaw has a CVSS score of 7.1, indicating a high severity impact. The EPSS score is less than 1%, suggesting a very low probability of known exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. While the description does not specify an explicit attack vector, it is inferred that an authorized attacker could exploit the flaw by exploiting a flaw in the partitioning logic to gain access to other spaces. Vulnerability mitigation requires upgrading to version 6.13, and post‑patch hardening measures are recommended.

Generated by OpenCVE AI on August 1, 2026 at 08:38 UTC.

Remediation

Vendor Solution

Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13. To further enhance security after applying the update:  * Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet.  * Restrict operator-level accounts to the minimum required and apply least-privilege principles.  * If feasible, disable the partitioning feature and operate under a single partition.  * When strong tenant separation is required, consider running separate Space instances (isolated environments) rather than relying solely on logical partitioning.


OpenCVE Recommended Actions

  • Upgrade SALTO ProAccess Space to version 6.13 or later
  • Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet
  • Restrict operator‑level accounts to minimum required duties and apply least‑privilege principles
  • If feasible, disable logical partitioning (tenancy) and operate under a single partition
  • When strong tenant separation is required, consider running separate Space instances rather than relying on logical partitioning

Generated by OpenCVE AI on August 1, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Saltosystem
Saltosystem proaccess Space
Vendors & Products Saltosystem
Saltosystem proaccess Space

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product.
Title SALTO ProAccess Space Authorization Bypass Through User-Controlled Key
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Saltosystem Proaccess Space
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-17T13:21:12.776Z

Reserved: 2026-06-10T14:40:08.574Z

Link: CVE-2026-11889

cve-icon Vulnrichment

Updated: 2026-07-17T13:21:08.842Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:45:02Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key