---
id: CVE-2026-105275
title: >-
  Satel Netco Design versions prior to v2.1.7 contains a relative path traversal
  vulnerability in its data import functionality
summary: >-
  Satel Netco Design versions prior to v2.1.7 contains a relative path traversal
  vulnerability in its data import functionality. An authenticated user with
  Viewer privileges could access file paths outside the intended directory and
  use ob…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-23
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T14:17:11.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105275'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00263
epssPercentile: 0.16697
ingestedAt: '2026-10-08T23:16:47.388Z'
---

## Overview

Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
