PatchSiren cyber security CVE debrief
CVE-2026-105275 Satel CVE debrief
PatchSiren debrief for CVE-2026-105275: Satel Netco Design Relative Path Traversal. This vulnerability affects Satel Netco Design versions prior to v2.1.7, allowing an authenticated user with Viewer privileges to access file paths outside the intended directory via a relative path traversal vulnerability in its data import functionality. Defenders should assess exposure, verify user privileges and access controls, and monitor for suspicious file access attempts to determine whether files exist on the host system.
- Vendor
- Satel
- Product
- Satel Netco Design
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Satel Netco Design deployments, security teams, and vulnerability management teams should assess exposure and verify user privileges and access controls. They should also monitor for suspicious file access attempts and perform inventory checks to identify vulnerable systems. Additionally, operators and platform administrators should be aware of the potential impact and take necessary precautions to prevent exploitation.
Why it matters
CVE-2026-105275 is a relative path traversal vulnerability in Satel Netco Design versions prior to v2.1.7. Defenders should verify user privileges and access controls, monitor for suspicious file access attempts, and perform inventory checks to identify vulnerable systems.
- Verification of user privileges and access controls to prevent unauthorized file access
- Monitoring for suspicious file access attempts to detect potential exploitation
- Inventory checks for Satel Netco Design versions prior to v2.1.7 to identify vulnerable systems
Technical summary
Satel Netco Design versions prior to v2.1.7 contain a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system. The vulnerability can be mitigated by verifying user privileges and access controls, monitoring for suspicious file access attempts, and performing inventory checks to identify vulnerable systems. Defenders should focus on validating affected scope, severity, and vendor guidance.
Defensive priority
Medium priority for inventory checks and version verification
Recommended defensive actions
- Inventory checks for Satel Netco Design versions prior to v2.1.7
- Verification of user privileges and access controls
- Monitoring for suspicious file access attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the relative path traversal vulnerability in Satel Netco Design versions prior to v2.1.7. An authenticated user with Viewer privileges could access file paths outside the intended directory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105275 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105275
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105275 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105275
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Satel Netco Design Relative Path Traversal
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105275.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.