---
id: CVE-2026-105269
title: >-
  Satel Netco Design versions prior to v2.1.7 contains a stored cross site
  scripting vulnerability
summary: >-
  Satel Netco Design versions prior to v2.1.7 contains a stored cross site
  scripting vulnerability. An authenticated user with Network Operator
  privileges could store untrusted content that is rendered without adequate
  neutralization. Succ…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:26.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105269'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
ingestedAt: '2026-10-08T23:16:47.387Z'
---

## Overview

Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
