Dell has released a major security update for its Container Storage Modules after identifying a collection of vulnerabilities that can expose storage credentials, tenant resources and Kubernetes nodes. The most serious issues are remotely reachable without authentication and received the maximum CVSS score of 10.0.
The flaws affect Dell CSM releases before version 1.17.0, while Dell lists version 1.18.0 and later as containing the fixes. The affected surface includes CSM Authorization, the CSM Operator, Container Storage Interface components and several bundled Go libraries. Dell says there are no workarounds or mitigations, leaving a software upgrade as the essential response.
Two flaws earn a maximum severity score
CVE-2026-63688 is a missing-authentication issue in the csm-authorization-storage gRPC server shipped with CSM Authorization 2.4.0. An unauthenticated attacker could retrieve administrator credentials for registered storage arrays. Because the service supports multiple Dell storage families, a successful attack could extend beyond a single volume or workload.
Possession of backend administrative credentials could allow changes to storage configuration, access to sensitive data, disruption of applications or the creation of persistent access. Storage control is a particularly sensitive trust boundary in container environments: even when compute workloads are segmented, shared storage can hold secrets, databases and business-critical state.
The second CVSS 10 issue, CVE-2026-63692, affects the authorization proxy and tenant service in the same CSM Authorization release. Critical functions can be reached without the expected identity check, enabling a network attacker to bypass authentication and rise to administrative privilege. Dell warns that storage resources across tenants may consequently be exposed or altered.
Hard-coded secrets and Kubernetes escalation
A third critical problem, CVE-2026-54472, involves hard-coded credentials. An unauthenticated attacker could create cryptographically valid administrative JSON Web Tokens and use them against the CSM Authorization proxy. Dell scored the vulnerability at 9.8 and advises customers to rotate JWT signing secrets after installing the update.
The advisory also calls out legacy karavi-authorization guidance that used the value “supersecret” as a signing secret alongside a real token example. Deployments that copied the example and never replaced the secret may remain susceptible to forged tokens. Updating code alone would not invalidate a secret that an attacker may already know, which is why rotation is a required companion action.
Kubernetes operators face additional risks. CVE-2026-67269, rated 9.9, could let a low-privileged user create a malicious ContainerStorageModule resource and gain root access to nodes. CVE-2026-67273, rated 9.6, involves template injection that can expose Kubernetes Secrets and permit creation of cluster-wide role-based access control resources. Both paths can turn modest permissions into broad control.
Broader update scope
Dell’s update also covers certificate-validation failures, missing authorization in the CSI Driver for PowerMax and sensitive information written to logs. Drivers for PowerFlex, PowerMax and PowerStore are among the affected components. Fixes for third-party packages include updates to Go cryptography, networking, JWT and protobuf libraries.
This breadth makes inventory important. Teams should identify every cluster running Dell CSM, not just the clusters believed to use the authorization module. They should also determine whether vulnerable services were externally reachable or exposed across less-trusted internal network segments.
What defenders should do now
- Upgrade all affected Dell CSM deployments to version 1.18.0 or later.
- Rotate JWT signing secrets and storage-array administrative credentials.
- Review CSM Authorization logs and administrative-token use for anomalies.
- Audit Kubernetes custom resources, Secrets access and cluster-scoped RBAC changes.
- Check nodes and storage arrays for unexpected accounts, configuration changes or persistence.
Because several flaws need no credentials and no compensating workaround exists, exposed services should be isolated until the upgrade is complete. Organizations should assume that credentials accessible through a vulnerable deployment may require replacement, especially where logging cannot prove that the affected endpoints were never reached.
Source: Cyber Security News, based on Dell security advisory DSA-2026-448.
Leave a Reply
You must be logged in to post a comment.