Junglewise Threat Intelligence

CVE-2026-11844: IEI iVEC Virtualization Edge Computer arbitrary file read

CVE-2026-11844 · Severity: medium · CVSS 4.9 · Published 2026-06-12

Technologies: IEI Integration Corp iVEC TANK-XM811. Vendors: IEI Integration Corp.

Executive brief

The iVEC-IEI Virtualization Edge Computer, used for industrial edge computing and virtualization, contains a security flaw that allows an authorized user with high-level privileges to read sensitive system files. An attacker could exploit this to access configuration data or other confidential information stored on the device. This could lead to further unauthorized access or the exposure of proprietary operational data.

Technical details

An arbitrary file read vulnerability (CWE-22) exists in the IEI Integration Corp iVEC TANK-XM811 virtualization edge computer. The flaw is caused by improper limitation of a pathname to a restricted directory, commonly known as path traversal. A remote attacker with high privileges (PR:H) can exploit this vulnerability to access and read files outside of the intended web or application directory. Successful exploitation allows for the disclosure of sensitive system information. The issue is resolved in version v1.0.4 and later.

Affected products

  • IEI Integration Corp iVEC TANK-XM811 before v1.0.4

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2026-06-12: patched

References

Related threats