{"id":"CVE-2026-101024","title":"Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality","summary":"Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-23"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:26:32.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101024","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd"],"ingestedAt":"2026-10-08T22:11:53.856Z","slug":"CVE-2026-101024","body":"## Overview\n\nSatel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}