ics-otregulatorNewsThe Broadside1 min read

CISA flags SALTO ProAccess Space partition bypass

Logical tenancy is not a security boundary when one valid operator account can cross every door group it was meant to contain.


TL;DR

CISA published ICSA-26-197-07 for CVE-2026-11889 in SALTO ProAccess Space versions before 6.13. Installations using the tenancy or logical partition feature allow an authenticated operator to bypass authorization and access spaces outside the assigned partition. Contractors, C3PAOs and municipal IT teams using SALTO for multi-tenant facilities should patch to 6.13 and reassess whether partitioning is carrying more trust than it deserves.

This is not a remote unauthenticated door-opener, which matters. CISA says exploitation requires valid authenticated operator credentials and the partition feature to be enabled, and that installations without partitioning are not affected. It also says no known public exploitation specifically targeting CVE-2026-11889 has been reported to CISA. That keeps the advisory in practical patch-now territory, not panic territory.

The uncomfortable part is the mitigation list. SALTO’s fix is ProAccess Space 6.13, followed by familiar controls: keep the system off the public internet, restrict operator accounts and apply least privilege. But CISA’s advisory also points users toward disabling partitioning or running separate Space instances when strong tenant separation is required. For contractors, C3PAOs and municipal facilities using one access-control installation to separate tenants, departments or restricted areas, that is the operative sentence. If the boundary matters, do not make a logical partition the only thing standing between a valid credential and the wrong room.


Published ·Deep Fathom