PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105275 Satel CVE debrief

PatchSiren debrief for CVE-2026-105275: Satel Netco Design Relative Path Traversal. This vulnerability affects Satel Netco Design versions prior to v2.1.7, allowing an authenticated user with Viewer privileges to access file paths outside the intended directory via a relative path traversal vulnerability in its data import functionality. Defenders should assess exposure, verify user privileges and access controls, and monitor for suspicious file access attempts to determine whether files exist on the host system.

Vendor
Satel
Product
Satel Netco Design
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Defenders responsible for Satel Netco Design deployments, security teams, and vulnerability management teams should assess exposure and verify user privileges and access controls. They should also monitor for suspicious file access attempts and perform inventory checks to identify vulnerable systems. Additionally, operators and platform administrators should be aware of the potential impact and take necessary precautions to prevent exploitation.

Why it matters

CVE-2026-105275 is a relative path traversal vulnerability in Satel Netco Design versions prior to v2.1.7. Defenders should verify user privileges and access controls, monitor for suspicious file access attempts, and perform inventory checks to identify vulnerable systems.

  • Verification of user privileges and access controls to prevent unauthorized file access
  • Monitoring for suspicious file access attempts to detect potential exploitation
  • Inventory checks for Satel Netco Design versions prior to v2.1.7 to identify vulnerable systems

Technical summary

Satel Netco Design versions prior to v2.1.7 contain a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system. The vulnerability can be mitigated by verifying user privileges and access controls, monitoring for suspicious file access attempts, and performing inventory checks to identify vulnerable systems. Defenders should focus on validating affected scope, severity, and vendor guidance.

Defensive priority

Medium priority for inventory checks and version verification

Recommended defensive actions

  • Inventory checks for Satel Netco Design versions prior to v2.1.7
  • Verification of user privileges and access controls
  • Monitoring for suspicious file access attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the relative path traversal vulnerability in Satel Netco Design versions prior to v2.1.7. An authenticated user with Viewer privileges could access file paths outside the intended directory.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105275 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105275

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105275 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105275

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Satel Netco Design Relative Path Traversal

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105275.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.