CVE-2026-101024: Satel Netco Design Relative path traversal
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Satel Netco Designto a version that resolves this vulnerability.Fixed in 2.1.7
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with Viewer privileges can exploit the vulnerable data export functionality. Exploitation is network-accessible and does not require user interaction.
Which deployments are affected?
Satel Netco Design versions prior to v2.1.7 are affected. The provided information does not state whether Viewer privileges are assigned by default.
What access does an attacker gain through successful exploitation?
An attacker can write attacker-influenced content to filesystem locations accessible to the application service, resulting in unauthorized file creation or modification. Under certain conditions, this may lead to arbitrary code execution.