SALTO ProAccess Space

MonitorCVSS 6.5ICS-CERT ICSA-26-197-07Jul 16, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An authenticated operator in SALTO ProAccess Space can escalate privileges and gain unauthorized access to spaces outside their assigned partition. The vulnerability exists because the access control system fails to properly enforce partition boundaries when an authenticated user attempts to escalate their privilege level. Exploitation requires valid operator credentials and depends on the partition (tenancy) feature being active. Installations using a single partition without partitioning enabled are not affected.

What this means
What could happen
An authenticated operator with access to ProAccess Space could gain administrative control over restricted areas or tenant spaces they should not have access to, potentially bypassing physical access control policies and allowing unauthorized entry into secured zones.
Who's at risk
Organizations using SALTO ProAccess Space as their access control system, particularly those with multiple tenants or business units that require partition-based separation. This includes municipal facilities (water authorities, electric utilities, municipal buildings), healthcare facilities, office parks, and any multi-tenant real estate using ProAccess Space with the partitioning feature enabled.
How it could be exploited
An attacker with valid operator credentials logs into ProAccess Space and exploits a privilege escalation flaw to escalate their access level. Once escalated, they can view and modify access rules for spaces (rooms, zones, or facilities) assigned to other partitions they should not have visibility into. This could allow them to grant themselves or others access to restricted areas.
Prerequisites
  • Valid authenticated operator credentials for ProAccess Space
  • Partition feature must be enabled on the installation
  • Access to the ProAccess Space management interface or API
Remotely exploitableAuthentication required but attacker is insiderPartition feature must be enabledAffects logical access controlsCould lead to unauthorized physical facility access
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
ProAccess Space<6.13Fix available
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict operator-level accounts to minimum required roles and apply least-privilege access principles
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpgrade ProAccess Space to version 6.13 or later
Long-term hardening
0/2
HARDENINGPlace ProAccess Space on a protected internal network and do not expose it directly to the Internet
HARDENINGIf strong tenant separation is required, disable logical partitioning and run separate isolated ProAccess Space instances instead
API: /api/v1/advisories/358cefe0-0287-476a-a668-a1c51af7e5cc

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.