Skip to content
TrustList
News

Dell Container Storage Modules: maximum-severity flaws give attackers storage admin credentials and control; update to 1.18.0

Editorial

By TrustList Editorial

Dell has fixed two maximum-severity flaws in the Authorization module of Container Storage Modules, CVE-2026-63688 and CVE-2026-63692, plus four critical ones, which can expose storage-array admin credentials and Kubernetes secrets. Update to 1.18.0.

About Dell Container Storage Modules: maximum-severity flaws give attackers storage admin credentials and control; update to 1.18.0

Dell Container Storage Modules: maximum-severity flaws give attackers storage admin credentials and control; update to 1.18.0

2 October 2026 — Dell has fixed six critical vulnerabilities in Container Storage Modules (CSM), the software that connects Kubernetes clusters to Dell storage arrays and adds features such as authorisation, replication and observability. Two are rated maximum severity. BleepingComputer reported Dell's advisory on 2 October 2026. All versions before 1.18.0 are affected.

Not yet independently verified. This rests on BleepingComputer’s report of Dell’s advisory DSA-2026-448; Dell’s own page could not be read from our location. No exploitation has been reported. We will update this when it can be confirmed, and remove this note.

The flaws

According to the report:

  • CVE-2026-63688 (maximum severity): in the CSM Authorization module, an unauthenticated remote attacker can obtain the storage-backend administrator credentials for the registered arrays and bypass authorisation, giving full administrative control of the storage.
  • CVE-2026-63692 (maximum severity): a bypass of authentication in the authorisation proxy and tenant service. Dell says it "enables an unauthenticated attacker to gain complete administrative control" of the authorisation service and storage resources.
  • Four more critical flaws: CVE-2026-67269 (root access on cluster nodes), CVE-2026-54472 (administrative access to the authorisation proxy), CVE-2026-61421 (forged authentication tokens with administrator rights) and CVE-2026-67273 (bypass of Kubernetes access controls to reach secrets across the cluster).

Dell's instruction is to "upgrade at the earliest opportunity" to 1.18.0 or later.

Why it matters

CSM Authorization exists to let several teams or tenants share Dell arrays safely from Kubernetes, so it holds the keys to the storage itself. A flaw that hands an attacker the array administrator credentials reaches every volume on those arrays, not only the cluster that was attacked, including backups and the data of other tenants.

What to do

  • Find every cluster running Dell CSM, especially the Authorization module, and upgrade to 1.18.0 or later.
  • Rotate the storage administrator credentials registered with CSM Authorization after upgrading, and the tokens it issued.
  • Restrict network access to the authorisation proxy and tenant service to the clusters that need it.
  • Review array audit logs for administrative actions you cannot explain.
  • If a managed-service provider runs your Kubernetes storage, ask when it upgraded.

Sources

Categories & features