Junglewise Threat Intelligence

CVE-2026-11845: IEI iVEC Virtualization Edge Computer OS command injection

CVE-2026-11845 · Severity: high · CVSS 7.2 · Published 2026-06-12

Technologies: IEI Integration Corp iVEC TANK-XM811. Vendors: IEI Integration Corp.

Executive brief

The iVEC-IEI Virtualization Edge Computer, an industrial computing device used for edge processing and virtualization, contains a security flaw that allows an authorized user with high-level privileges to execute unauthorized system commands. If exploited, an attacker could take full control of the device, potentially leading to data theft, service disruption, or unauthorized access to the local network. This vulnerability requires the attacker to already have administrative credentials.

Technical details

An OS command injection vulnerability (CWE-78) exists in the IEI Integration Corp iVEC TANK-XM811 virtualization edge computer. The flaw allows a remote attacker with high privileges (administrative access) to inject and execute arbitrary operating system commands on the underlying host. The attack is carried out over the network without requiring user interaction. Successful exploitation grants the attacker full system-level control, enabling them to read, modify, or delete any data and potentially pivot to other systems on the network. The vulnerability is addressed in version v1.0.4.

Affected products

  • IEI Integration Corp iVEC TANK-XM811 before v1.0.4

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2026-06-12: patched: Update to v1.0.4 or later

References

Related threats