CVE-2026-104628: Satel Netco Design Inefficient Regular Expression Complexity

Published Oct 8, 2026
·
Updated

Satel Netco Design versions prior to v2.1.7 contains an inefficient regular expression complexity vulnerability. An authenticated user with Viewer privileges could submit crafted search input that causes excessive processing, potentially degrading the availability of the application.

Affected Software

1 affected component
Satel Netco Design Netco Design<2.1.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Satel Netco Design to a version that resolves this vulnerability.

    Fixed in 2.1.7

Event History

Oct 8, 2026
CVE Published
via MITRE·09:24 PM
Data Sourced
via MITRE·09:24 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated to Satel Netco Design and have Viewer privileges. The attack can be performed remotely by submitting crafted search input.

2

Which deployments are affected?

Satel Netco Design versions earlier than v2.1.7 are affected. The provided information does not identify any configuration prerequisite beyond access to the application's search functionality.

3

What is the impact of successful exploitation?

Crafted search input can trigger excessive processing due to inefficient regular-expression complexity. This can degrade application availability; no confidentiality or integrity impact is identified.

4

What should be done if an affected version is in use?

Upgrade to v2.1.7 or later. If upgrading cannot occur immediately, restrict Viewer-level access to trusted users and monitor or limit potentially abusive search activity where operationally possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203