---
id: CVE-2026-101024
title: >-
  Satel Netco Design versions prior to v2.1.7 contains a relative path traversal
  vulnerability in its data export functionality
summary: >-
  Satel Netco Design versions prior to v2.1.7 contains a relative path traversal
  vulnerability in its data export functionality. An authenticated user with
  Viewer privileges could write attacker influenced content to file system
  locations …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-23
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:26:32.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101024'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
ingestedAt: '2026-10-08T22:11:53.856Z'
---

## Overview

Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
