Back Rescana Critical Dell Container Storage Modules (CSM) Vulnerabilities Expose Kubernetes ...
Dell has disclosed multiple critical vulnerabilities in its Container Storage Modules (CSM) , which integrate Dell enterprise storage arrays with Kubernetes environments. The most severe flaws (CVSS 10.0) allow unauthenticated remote attackers to gain full administrative control over storage infrastructure, access backend credentials, escalate privileges, and bypass Kubernetes access controls. Immediate patching is required to mitigate the risk of catastrophic compromise. While there is no evidence of public exploitation or proof-of-concept code for these specific vulnerabilities as of October 2026, the technical severity and historical targeting of Dell products by advanced persistent threat (APT) groups underscore the urgency of remediation.
Technical Information
The vulnerabilities affect Dell Container Storage Modules (CSM) , which provide integration between Kubernetes clusters and Dell storage arrays, including PowerStore , PowerScale , PowerFlex , PowerMax , and Unity XT . The flaws are present in all CSM versions prior to 1.18.0. The most critical issues are as follows:
CVE-2026-63688 (CVSS 10.0): This vulnerability resides in the CSM Authorization component (csm-authorization-storage gRPC server) and is classified as Missing Authentication for Critical Function. It allows unauthenticated remote attackers to access storage backend administrator credentials for all registered storage arrays and bypass authorization, resulting in full administrative control over the storage infrastructure. Exploitation requires no authentication and can be performed remotely over the network.
CVE-2026-63692 (CVSS 10.0): Affecting the Authorization proxy and tenant service, this flaw also involves Missing Authentication for Critical Function. Attackers can bypass authentication controls and gain admin privileges, enabling unauthorized access and manipulation of storage resources across all tenants.
CVE-2026-67269 (CVSS 9.9): This vulnerability in the CSM Operator (ContainerStorageModule Custom Resource reconciler) is due to Improper Privilege Management. Low-privileged remote attackers can escalate privileges and gain root-level access on cluster nodes, compromising all nodes in the Kubernetes cluster.
CVE-2026-54472 (CVSS 9.8): In the CSM Authorization component, the use of hard-coded credentials allows attackers to forge cryptographically valid administrative tokens, granting unauthorized admin access to the CSM Authorization proxy.
CVE-2026-61421 (CVSS 9.8): In the archived karavi-authorization component, the use of a hard-coded cryptographic key enables attackers who know the public signing secret to forge authentication tokens and gain admin privileges.
CVE-2026-67273 (CVSS 9.6): This vulnerability in CSM is due to Improper Neutralization in the Template Engine. Low-privileged attackers can gain cluster-wide read access to Kubernetes Secrets and create cluster-scoped RBAC resources, bypassing intended access controls.
Other CVEs addressed in the advisory include CVE-2026-67270, CVE-2026-76105, CVE-2026-61411, CVE-2026-70411, CVE-2026-63689, CVE-2026-63691, and CVE-2026-63690. For a comprehensive list, refer to the Dell advisory .
The attack vector for these vulnerabilities is remote and network-based, requiring no authentication. The potential impact includes full compromise of storage infrastructure, credential theft, privilege escalation, and cluster-wide Kubernetes compromise. Affected environments are Kubernetes clusters using Dell CSM for storage integration.
Exploitation in the Wild
As of October 2026, there are no public reports of exploitation of these specific CSM vulnerabilities. The vulnerabilities are not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and thus there is no CISA-confirmed active exploitation. However, historical context is important: state- groups such as Lazarus and UNC6201/Silk Typhoon have previously exploited Dell vulnerabilities for privilege escalation and malware deployment. CISA has also issued emergency directives for rapid patching of Dell vulnerabilities in the past, highlighting the criticality of timely remediation.
APT Groups using this vulnerability
There is no direct evidence linking specific APT groups to exploitation of these new CSM vulnerabilities. However, the following groups have a history of targeting Dell products:
Lazarus Group (North Korea): Known for exploiting Dell vulnerabilities such as CVE-2021-21551, with a focus on government, defense, and financial sectors globally, especially in the US, South Korea, and Western countries.
UNC6201 / Silk Typhoon (China): Previously exploited Dell hardcoded credential vulnerabilities in 2024, targeting government agencies and critical infrastructure in the US, Europe, and Asia-Pacific.
Given the technical severity and the attractiveness of storage infrastructure as a target, organizations in these sectors should be especially vigilant.
Affected Product Versions
The affected products are Dell Container Storage Modules (CSM) supporting PowerStore , PowerScale , PowerFlex , PowerMax , and Unity XT . All CSM versions prior to 1.18.0 are vulnerable. The remediated version is CSM 1.18.0 or later. Customers must upgrade to 1.18.0 or newer to be protected.
Workaround and Mitigation
The primary mitigation is to upgrade CSM to version 1.18.0 or later immediately. In addition, organizations should rotate all JWT signing secrets if using CSM Authorization, audit for unauthorized access or privilege escalation in Kubernetes and storage logs, and monitor for indicators of compromise as described below. There are no effective workarounds for the most critical vulnerabilities; patching is mandatory.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. As of the time of writing, no public indicators of compromise have been published for these vulnerabilities.
Dell Security Advisory DSA-2026-448
BleepingComputer: Dell asks admins to patch max severity CSM flaws as soon as possible
TheHackerNews: Dell CSM Flaws Enable Unauthenticated Admin Access
: SecOpsDaily thread
Rescana is here for you
Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform that enables organizations to continuously monitor, assess, and mitigate cyber risks across their supply chain and vendor ecosystem. Our platform leverages advanced analytics and threat intelligence to help you stay ahead of emerging threats and regulatory requirements. We are happy to answer any questions at [email protected].
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
