CVE-2026-31216 Details
Description
The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentication, authorization, and input validation mechanisms. Unauthenticated remote attackers can send crafted requests with a user-controlled object_name path parameter to delete arbitrary files from the underlying MinIO storage system. Successful exploitation leads to data loss and denial of service.
A vulnerability allowing unauthorized deletion of arbitrary files has been identified in the Nexent backend service version 1.7.5.2. This issue arises within the file management API, specifically at the DELETE /storage/{object_name:path} endpoint, which lacks authentication, authorization, and proper input validation. As a result, unauthenticated remote attackers can exploit this vulnerability by sending crafted requests that include a user-controlled object_name path parameter, leading to the deletion of arbitrary files from the MinIO storage system. The successful exploitation of this vulnerability causes data loss and can disrupt service availability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ModelEngine-Group/nexent | [email protected] | Product |
| https://www.notion.so/CVE-2026-31216-35d1e139318881208297f0fbd8005f68 | [email protected] | MitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-552 | Files or Directories Accessible to External Parties | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nexent nexent | 1.7.5.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |