The Cybersecurity and Infrastructure Security Agency (CISA) published advisory ICSA-26-281-03 on October 8, 2026, detailing four security vulnerabilities in Satel Netco Design, a software package used in communications critical infrastructure. The vendor, Satel of Finland, confirmed that all affected versions are those prior to v2.1.7.
The vulnerabilities are:
- CVE-2026-105269: A stored cross-site scripting (XSS) vulnerability allowing an authenticated user with Network Operator privileges to store untrusted content that is rendered without adequate neutralization. Successful exploitation could enable script execution in another user's browser when the affected content is viewed. CVSS 3.1 base score: 6.8 (MEDIUM); CVSS 4.0 base score: 8.5 (HIGH).
- CVE-2026-104628: An inefficient regular expression complexity vulnerability. An authenticated user with Viewer privileges could submit crafted search input that causes excessive processing, potentially degrading the availability of the application. CVSS 3.1 base score: 6.5 (MEDIUM); CVSS 4.0 base score: 7.1 (HIGH).
- CVE-2026-105275: A relative path traversal vulnerability in the data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system. CVSS 3.1 base score: 4.3 (MEDIUM); CVSS 4.0 base score: 5.3 (MEDIUM).
- CVE-2026-101024: A relative path traversal vulnerability in the data export functionality. An authenticated user with Viewer privileges could write attacker-influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution. CVSS 3.1 base score: 4.5 (MEDIUM); CVSS 4.0 base score: 5.3 (MEDIUM).
All four vulnerabilities require authenticated access. The XSS flaw (CVE-2026-105269) carries the highest severity, with the CVSS 4.0 vector reflecting potential impacts on confidentiality, integrity, and availability. The regex complexity issue (CVE-2026-104628) could be leveraged for denial-of-service conditions. The two path traversal flaws could allow unauthorized file access, creation, or modification.
Satel has released version 2.1.7 as a fix and advises all users to update immediately. CISA notes that the software is deployed worldwide and is relevant to the Communications critical infrastructure sector.