CVE-2026-11847
Description
Authenticated remote attackers can exploit a path traversal vulnerability in IEI iVEC TANK-XM811 before v1.0.4 to create directories in unintended system paths.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated remote attackers can exploit a path traversal vulnerability in IEI iVEC TANK-XM811 before v1.0.4 to create directories in unintended system paths.
Vulnerability
The iVEC-IEI Virtualization Edge Computer (model iVEC TANK-XM811) running versions prior to v1.0.4 contains a Path Traversal vulnerability (CVE-2026-11847). An authenticated remote attacker can exploit this flaw to create directories outside the intended scope, leveraging improper input validation in file system operations. [1][2]
Exploitation
An attacker must have valid credentials to access the affected device remotely over the network. No user interaction is required. By sending specially crafted requests, the attacker can traverse directory paths and create new directories in arbitrary system locations, bypassing access controls. [1][2]
Impact
Successful exploitation allows the attacker to create directories in unintended system paths, achieving a low integrity impact (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). This could disrupt normal system operations or be a precursor to further attacks, such as planting configuration files or exhausting disk space. [1][2]
Mitigation
IEI Integration Corp released a fix in version v1.0.4 of iVEC TANK-XM811. All users should update to v1.0.4 or later. No workarounds are documented. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of publication. [1][2]
AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2News mentions
0No linked articles in our index yet.