Executive brief
SALTO ProAccess Space, a software suite used for managing electronic building access and security, contains a flaw in its multi-tenant partitioning feature. An authorized user with low-level access could exploit this vulnerability to gain unauthorized access to other logical partitions or 'spaces' within the system that they are not permitted to manage. This could lead to unauthorized changes in access control settings or security configurations across different departments or tenants within the same facility.
Technical details
The vulnerability is classified as an Authorization Bypass Through User-Controlled Key (CWE-639) within the tenancy/logical partition feature of SALTO ProAccess Space. An authenticated attacker with valid operator credentials can manipulate keys or identifiers to escalate their privileges and access partitions outside of their assigned scope. This issue only affects installations where the partitioning feature is enabled. Successful exploitation allows the attacker to perform unauthorized modifications across any space managed by the system. The vulnerability is addressed in version 6.13.
Affected products
- SALTO Systems ProAccess Space < 6.13
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
- 2026-07-16: patched: Fixed in version 6.13