Junglewise Threat Intelligence

CVE-2026-11847: IEI iVEC-IEI Virtualization Edge Computer path traversal

CVE-2026-11847 · Severity: medium · CVSS 4.3 · Published 2026-06-12

Technologies: IEI Integration Corp iVEC TANK-XM811. Vendors: IEI Integration Corp.

Executive brief

The iVEC-IEI Virtualization Edge Computer, a device used for industrial edge computing and virtualization, contains a security flaw. An authorized user can exploit this vulnerability to create new folders in restricted areas of the system where they should not have access. While this does not directly expose data, it could be used to disrupt system organization or as a stepping stone for more complex attacks.

Technical details

A path traversal vulnerability (CWE-22) exists in the IEI Integration Corp iVEC TANK-XM811 virtualization edge computer. The flaw allows a remote attacker with low-level authentication (PR:L) to bypass directory restrictions and create arbitrary directories in unintended system paths. This is achieved by submitting specially crafted input containing path traversal sequences (e.g., ../) to affected endpoints. The vulnerability is addressed in version v1.0.4.

Affected products

  • IEI Integration Corp iVEC TANK-XM811 before v1.0.4

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory
  • 2026-06-12: patched: Fixed in version v1.0.4

References

Related threats