VYPR
Medium severity4.3NVD Advisory· Published Jun 12, 2026

CVE-2026-11847

CVE-2026-11847

Description

Authenticated remote attackers can exploit a path traversal vulnerability in IEI iVEC TANK-XM811 before v1.0.4 to create directories in unintended system paths.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated remote attackers can exploit a path traversal vulnerability in IEI iVEC TANK-XM811 before v1.0.4 to create directories in unintended system paths.

Vulnerability

The iVEC-IEI Virtualization Edge Computer (model iVEC TANK-XM811) running versions prior to v1.0.4 contains a Path Traversal vulnerability (CVE-2026-11847). An authenticated remote attacker can exploit this flaw to create directories outside the intended scope, leveraging improper input validation in file system operations. [1][2]

Exploitation

An attacker must have valid credentials to access the affected device remotely over the network. No user interaction is required. By sending specially crafted requests, the attacker can traverse directory paths and create new directories in arbitrary system locations, bypassing access controls. [1][2]

Impact

Successful exploitation allows the attacker to create directories in unintended system paths, achieving a low integrity impact (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). This could disrupt normal system operations or be a precursor to further attacks, such as planting configuration files or exhausting disk space. [1][2]

Mitigation

IEI Integration Corp released a fix in version v1.0.4 of iVEC TANK-XM811. All users should update to v1.0.4 or later. No workarounds are documented. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of publication. [1][2]

AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.