CVE 9.1 CRITICAL

CVE-2026-31216_CVE-2026-31216

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentication, authorization, and input validation mechanisms. Unauthenticated remote attackers can send crafted requests with a user-controlled object_name path parameter to delete arbitrary files from the underlying MinIO storage system. Successful exploitation leads to data loss and denial of service.

AI Analysis

Unauthenticated arbitrary file deletion vulnerability in nexent backend service

Basic Information

ID CVE-2026-31216
Source mitre
Published May 12, 2026 at 00:00
Modified May 13, 2026 at 14:00

Affected Product

Vendor ModelEngine-Group
Product nexent
Version 1.7.5.2
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor ModelEngine-Group
Product nexent
Version 1.7.5.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.