Dell Patches Critical CSM Flaws Allowing Unauthenticated Admin Access and Kubernetes ...
Dell has released security updates for six critical vulnerabilities in Container Storage Modules (CSM) that could let unauthenticated attackers gain administrative access to storage backends and root-level control over Kubernetes cluster nodes. All versions prior to 1.17.0 are affected; version 1.18.0 contains the fixes.
Dell Technologies has disclosed six critical security vulnerabilities in its Container Storage Modules (CSM) that could allow unauthenticated attackers to seize administrative control of storage infrastructure and compromise entire Kubernetes clusters. The flaws, tracked as CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, and CVE-2026-67273, carry CVSS scores ranging from 9.6 to 10.0.
The vulnerabilities affect all CSM versions prior to 1.17.0. Dell has addressed them in version 1.18.0 and advises customers to update immediately and rotate any JWT signing secrets. No workarounds or mitigations exist beyond upgrading.
Authentication Bypass and Credential Theft
The most severe flaw, CVE-2026-63688 (CVSS 10.0), resides in the csm-authorization-storage gRPC server. A missing authentication check allows an unauthenticated remote attacker to obtain storage backend administrator credentials for all registered storage arrays across Dell's five supported product families.
"This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure," Dell stated in its advisory.
CVE-2026-63692 (CVSS 10.0) presents a similar authentication bypass in the authorization proxy and tenant service, enabling unauthenticated network attackers to gain administrative privileges and access or manipulate storage resources across all tenants.
Hard-Coded Secrets Enable Token Forgery
Two vulnerabilities stem from hard-coded cryptographic material. CVE-2026-54472 (CVSS 9.8) involves hard-coded credentials in the CSM Authorization module that let attackers forge cryptographically valid administrative tokens. CVE-2026-61421 (CVSS 9.8) exposes a hard-coded JWT signing key in the karavi-authorization component, allowing anyone with knowledge of the publicly available secret to forge authentication tokens and gain administrative access.
Kubernetes Cluster Compromise
CVE-2026-67269 (CVSS 9.9) represents an improper privilege management issue in the ContainerStorageModule Custom Resource reconciler. A low-privilege remote attacker can escalate privileges and gain root-level access on cluster nodes. Dell noted that a single custom resource submission can compromise all nodes in a Kubernetes cluster.
CVE-2026-67273 (CVSS 9.6) involves a template engine injection vulnerability that enables privilege escalation, sensitive information access, and unauthorized RBAC tampering. Dell warned that successful exploitation grants cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing intended Kubernetes access controls.
Urgent Patching Required
Given that Dell vulnerabilities (CVE-2021-21551 and CVE-2026-22769) have seen active exploitation, security teams should prioritize deploying CSM 1.18.0 immediately. The update addresses all six flaws. Organizations should also rotate JWT signing secrets and audit storage access policies for signs of unauthorized changes.
Dell Container Storage Modules provide persistent storage orchestration for Kubernetes environments across Dell's storage portfolio including PowerStore, PowerFlex, PowerScale, PowerMax, and Unity arrays. The authorization component serves as the central control plane for storage access policies and tenant isolation.
Security researchers and administrators can find detailed remediation guidance in Dell's security advisory DSA-2026-XXX and should verify successful upgrade to version 1.18.0 across all deployed CSM instances.
Source : thehackernews.com
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
