// 1 CRITICAL · 5 ZERO-DAY · 5 CVE · 2 EXPLOIT IN THE LAST 24H→
Dell has patched two maximum-severity vulnerabilities in Container Storage Modules. An unauthenticated attacker can bypass access controls and gain complete administrative privileges.

Dell has released Container Storage Modules 1.18.0 to close two maximum-severity vulnerabilities in the CSM Authorization module. The flaws, rated CVSS 10 by SecurityOnline.info, allow a remote, unauthenticated attacker to bypass access controls and assume full administrative privileges. Dell has not provided any workaround; the only protection is installing the patch.

Key Takeaways
  • Two CVSS 10 vulnerabilities in the CSM Authorization module enable authentication bypass on Dell storage backends.
  • CVE-2026-63688 exposes administrator credentials for all registered arrays; CVE-2026-63692 allows unauthorized access and potential manipulation of storage resources across tenants.
  • Four additional critical-severity CVEs (9.6–9.9) round out the bulletin, with impacts including root on cluster nodes and cluster-wide reading of Kubernetes objects.
  • Dell recommends upgrading to version 1.18.0 or later without offering temporary alternatives.

The gRPC Server That Requires No Authentication

The issue resides in the CSM Authorization module, the component that mediates authentication and authorization between Kubernetes clusters and Dell enterprise storage arrays. According to BleepingComputer, both maximum-severity flaws stem from a weakness classified as CWE-306: missing authentication for critical function. Functions that should have been accessible only to verified identities instead respond to anyone who queries them.

CVE-2026-63688 affects csm-authorization-storage, the gRPC server that manages communication with storage backends. A remote, unauthenticated attacker can extract the administrator credentials for all storage arrays registered in the system and, with those credentials, bypass authorization to gain complete administrative control over the infrastructure. The source reports Dell's statement: "This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants."

CVE-2026-63692 affects the authorization proxy and tenant service. Here, too, the absence of authentication allows bypassing controls and acquiring administrative privileges. The two flaws interact: the first provides access to credentials, the second allows bypassing access controls.

Six CVEs, Two Attack Families

Beyond the two maximum-severity vulnerabilities, Dell has fixed four critical-severity flaws that expand the attack surface from the storage layer to the Kubernetes cluster. CVE-2026-67269, rated CVSS 9.9 by SecurityOnline.info, allows a remote, unprivileged attacker to obtain root on cluster nodes. CVE-2026-54472 (CVSS 9.8) grants administrative access to the CSM Authorization proxy. CVE-2026-61421 (CVSS 9.8) enables forging authentication tokens to escalate privileges. CVE-2026-67273 (CVSS 9.6) allows bypassing Kubernetes access controls for cluster-wide reading.

The combination of these vulnerabilities illustrates the risk that an entry point in the Authorization module translates into storage administrative access and subsequent escalation within the cluster. The source does not specify whether these flaws can be chained into a single automated attack.

According to SecurityOnline.info, advisory DSA-2026-448 lists a total of 13 Dell-specific CVEs and 24 additional vulnerabilities in third-party Go libraries included in the CSM distribution. This dual register indicates an extended attack surface that is not limited to Dell proprietary code.

"CSM connects Kubernetes clusters to Dell storage arrays such as PowerMax, PowerFlex, and PowerStore. As a result, a flaw here reaches past the cluster into the arrays themselves" — SecurityOnline.info

PowerMax, PowerStore, and the Security Perimeter

The affected products are the five enterprise storage families supported by CSM: PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. These arrays run mission-critical workloads in on-premises and hybrid cloud environments. The typical architecture places these systems in isolated network segments, accessible only through APIs controlled by the Kubernetes orchestration plane.

The revelation that the mediating module—CSM Authorization—can be bypassed without credentials breaks this defense model. The attacker interacts directly with the gRPC server or proxy and obtains the highest available privilege level. According to BleepingComputer, Dell has stated that no workarounds exist; the only documented mitigation is upgrading.

What to Do Now

  • Upgrade to CSM 1.18.0 or later, as directed by Dell in the communication reported by BleepingComputer. Advisory DSA-2026-448 provides no exceptions for specific configurations.

Dell offers no temporary workarounds. The source does not specify pre-upgrade verification procedures or recommended installation timelines.

Context and Risk

According to SecurityOnline.info, Dell has not reported in-the-wild exploitation for these specific vulnerabilities, and no public proof-of-concept exploits have emerged. However, the maximum CVSS severity and the lack of workarounds make upgrading the only practical option for administrators.

The vulnerabilities fit a broader trend of flaws in storage drivers and modules for containers, where the complexity of integration between orchestrators and enterprise backends creates often-underestimated attack surfaces. The source provides no data on CSM prevalence in enterprise Kubernetes deployments or on the adoption rate of version 1.18.0.

This article is based primarily on editorial sources; the vendor advisory DSA-2026-448 has not been directly verified.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. blog.netmanageit.com
  3. dell.com
  4. securityonline.info
  5. deals.bleepingcomputer.com