PatchSiren cyber security CVE debrief
CVE-2026-31216 ModelEngine-Group CVE debrief
A critical unauthenticated arbitrary file deletion vulnerability exists in Nexent backend service version 1.7.5.2. The DELETE /storage/{object_name:path} endpoint lacks authentication, authorization, and input validation, allowing remote attackers to delete arbitrary files from the underlying MinIO storage system without credentials. Published 2026-05-12, modified 2026-05-26. CVSS 3.1 score 9.1 (Critical). Not listed in CISA KEV.
- Vendor
- ModelEngine-Group
- Product
- nexent
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-26
Who should care
Organizations running Nexent v1.7.5.2 backend services, particularly those exposing storage management APIs to untrusted networks. Security teams responsible for API gateway protection, MinIO storage deployments, and data loss prevention programs.
Technical summary
The Nexent v1.7.5.2 backend service exposes a file management API endpoint DELETE /storage/{object_name:path} without authentication, authorization, or input validation. The object_name path parameter is user-controlled and passed directly to the underlying MinIO storage system. Unauthenticated remote attackers can craft requests with arbitrary path values to delete any file accessible to the service account. This represents a critical integrity and availability impact with no confidentiality impact per CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H.
Defensive priority
critical
Recommended defensive actions
- Immediately restrict network access to Nexent v1.7.5.2 backend service DELETE /storage/{object_name:path} endpoint at network perimeter
- Implement authentication and authorization controls on all storage management API endpoints prior to production deployment
- Apply input validation and path sanitization to object_name parameters to prevent directory traversal and arbitrary file deletion
- Review MinIO storage bucket policies and implement least-privilege access controls
- Monitor for unauthorized DELETE requests to storage endpoints in application and infrastructure logs
- Contact vendor or consult third-party advisory for patch availability and official mitigation guidance
Evidence notes
NVD analyzed status confirms vulnerability details. CWE-552 (Files or Directories Accessible to External Parties) assigned. Third-party advisory with mitigation guidance available via Notion reference.
Official resources
-
CVE-2026-31216 CVE record
CVE.org
-
CVE-2026-31216 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, Mitigation
2026-05-12T16:16:13.493Z