CVE-2026-11846

HIGH

IEI Integration Corp|iVEC-IEI Virtualization Edge Computer - Arbitrary File Deletion

Title source: cna
STIX 2.1

Description

The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories,  resulting in data destruction or service disruption.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-10969-4c4e2-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-10970-e4b21-2.html

Scores

CVSS v3 8.1
EPSS 0.0057
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
IEI Integration Corp/iVEC TANK-XM811 < 1.0.4
Published Jun 12, 2026
Tracked Since Jun 12, 2026