Six Critical Flaws, Two of Them Perfect 10s
Dell has released security updates for Container Storage Modules (CSM) — the software layer that connects Kubernetes clusters to Dell's enterprise storage arrays — after researchers disclosed six critical vulnerabilities, two of which carry the maximum possible CVSS score of 10.0. Published as DSA-2026-448 on October 1, 2026, the advisory warns that unauthenticated attackers can chain these flaws to steal storage backend administrator credentials, bypass tenant isolation, and ultimately obtain root-level access on Kubernetes cluster nodes. Dell states no workarounds exist — the only remediation is to upgrade.
CSM is widely deployed in enterprise environments to provision and manage persistent storage for containerized workloads, linking Kubernetes to Dell's primary storage platforms, including PowerStore, PowerScale, PowerFlex, and PowerMax. Because the vulnerable components sit at the intersection of cluster orchestration and storage administration, successful exploitation gives an attacker a foothold that spans both the Kubernetes control plane and the underlying storage infrastructure.
Vulnerability Details
| CVE | CVSS | Type | Description |
|---|---|---|---|
| CVE-2026-63688 | 10.0 | Missing Authentication | Unauthenticated access to the csm-authorization-storage gRPC server in CSM Authorization 2.4.0 exposes storage backend administrator credentials for all registered arrays. |
| CVE-2026-63692 | 10.0 | Missing Authentication | A flaw in the authorization proxy and tenant service lets unauthenticated network attackers bypass login checks and gain administrator-level privileges across all tenants. |
| CVE-2026-67269 | 9.9 | Improper Privilege Management | Low-privilege attackers can abuse the ContainerStorageModule custom resource reconciler in the CSM Operator to achieve root-level access on cluster nodes. |
| CVE-2026-54472 | 9.8 | Hard-Coded Credentials | Hard-coded credentials in the CSM Authorization module allow attackers to forge cryptographically valid administrative tokens. |
| CVE-2026-61421 | 9.8 | Hard-Coded Cryptographic Key | Known JWT signing secrets in the legacy, archived karavi-authorization project allow attackers to forge authentication tokens with administrative privileges. |
| CVE-2026-67273 | 9.6 | Template Injection | A template-engine flaw lets low-privilege remote attackers escalate privileges, read cluster-wide Kubernetes Secrets, and manipulate RBAC configurations. |
All six flaws affect CSM versions prior to 1.17.0. Dell fixed them in version 1.18.0, which covers the CSM Authorization, CSM Operator, and CSI components, along with updated third-party Go library dependencies.
How the Attack Chain Works
Storage Credential Theft (CVE-2026-63688)
The csm-authorization-storage gRPC server was designed to broker credentials between CSM Authorization and the storage backends it manages, but it shipped with no authentication check on that interface. Any network-adjacent attacker who can reach the service can request and receive administrator credentials for every storage array registered with CSM — effectively a complete bypass of the csm-authorization security model. Dell notes this could let an attacker change storage configurations, exfiltrate data, disrupt workloads, or plant persistent access paths.
Tenant Isolation Bypass (CVE-2026-63692)
A companion flaw in the authorization proxy and tenant service allows attackers to skip login checks entirely, elevating to administrator level and manipulating storage resources across tenant boundaries — defeating the multi-tenant isolation CSM Authorization is meant to enforce.
Kubernetes Node Root Escalation (CVE-2026-67269)
Inside the cluster, the CSM Operator's reconciliation logic for the ContainerStorageModule custom resource can be abused by a low-privilege user who already has limited cluster access. By crafting a malicious custom resource, that user can escalate to root on the underlying Kubernetes nodes, moving from a constrained in-cluster identity to full host compromise.
Hard-Coded and Legacy Signing Secrets (CVE-2026-54472, CVE-2026-61421)
Two separate issues stem from credentials baked directly into code rather than generated per deployment. CVE-2026-54472 involves hard-coded credentials in the CSM Authorization module itself, while CVE-2026-61421 traces back to known JWT signing secrets left over in the archived karavi-authorization project (CSM Authorization's predecessor). In both cases, anyone who knows the secret — which is identical across every affected deployment — can mint valid administrative tokens without ever authenticating normally.
Template Injection and RBAC Abuse (CVE-2026-67273)
The sixth flaw lives in a template engine used by CSM components. A low-privilege remote attacker can inject template content that the engine evaluates with elevated trust, exposing cluster-wide Kubernetes Secrets and allowing the creation or modification of RBAC objects — a path to broad, persistent cluster privilege.
Impact Assessment
| Impact Area | Description |
|---|---|
| Storage Infrastructure | Full administrative control over PowerStore, PowerScale, PowerFlex, and PowerMax arrays registered with vulnerable CSM deployments. |
| Kubernetes Clusters | Root-level access on cluster nodes, undermining pod isolation and the security of every workload co-located on the affected node. |
| Credential Exposure | Storage admin credentials and JWT signing material may already be compromised in any internet- or network-exposed deployment; patching alone does not invalidate previously exfiltrated secrets. |
| Multi-Tenant Environments | Tenant isolation in CSM Authorization can be bypassed entirely, exposing one tenant's storage resources to another. |
| Data Integrity and Availability | Attackers with storage admin access can alter configurations, delete volumes, or disrupt production workloads relying on the affected arrays. |
| Exploitation Outlook | No active exploitation has been publicly reported as of this writing, but researchers note that a CVSS 10.0 unauthenticated bypass in storage control-plane software is typically reverse-engineered from the patch within days. |
Who Needs to Act
Storage and Platform Administrators
- Upgrade all Dell Container Storage Modules deployments to version 1.18.0 or later immediately — Dell has confirmed no workarounds or mitigations exist short of patching.
- Treat any internet-reachable or broadly network-accessible CSM Authorization deployment as potentially already compromised prior to patching.
- Discontinue any remaining deployments of the legacy, unsupported karavi-authorization project; it is not receiving further fixes.
Security Teams
- Rotate all JWT signing secrets used by CSM Authorization after upgrading — the old secrets should be considered burned regardless of whether exploitation is confirmed.
- Rotate storage backend administrator credentials for every array registered with CSM, since CVE-2026-63688 could have exposed them before the patch was applied.
- Review CSM Authorization access logs and audit administrative token usage for anomalous activity predating the upgrade.
- Inspect Kubernetes RBAC policies and
ContainerStorageModulecustom resources for unauthorized changes that may indicate prior exploitation of CVE-2026-67269 or CVE-2026-67273.
Kubernetes Platform Teams
- Restrict network access to CSM authorization services (the
csm-authorization-storagegRPC endpoint and the authorization proxy) to only the hosts and namespaces that require it. - Apply least-privilege RBAC to any identity capable of creating or modifying
ContainerStorageModulecustom resources, since CVE-2026-67269 specifically targets low-privilege users with limited cluster access. - Validate that node-level workload isolation controls (e.g., Pod Security admission, seccomp/AppArmor profiles) are in place as defense-in-depth against a future node-root scenario.
Key Takeaways
- Two of the six flaws score a perfect CVSS 10.0 — CVE-2026-63688 and CVE-2026-63692 both allow complete, unauthenticated bypass of CSM Authorization's security model.
- The vulnerabilities span both layers CSM connects — storage administration (PowerStore, PowerScale, PowerFlex, PowerMax) and Kubernetes cluster orchestration — so a single compromise can propagate across both.
- Patching does not retroactively protect exposed secrets. Organizations must rotate JWT signing secrets and storage admin credentials after upgrading, not just apply the update.
- All CSM versions prior to 1.17.0 are affected; version 1.18.0 is the only confirmed fix, and Dell has stated no interim workarounds exist.
- Legacy karavi-authorization deployments carry known, static JWT secrets (CVE-2026-61421) and should be retired rather than patched.
- No in-the-wild exploitation has been confirmed yet, but the severity and accessibility of these bugs make rapid weaponization likely — treat the upgrade as urgent, not routine maintenance.
Sources
- The Hacker News — Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
- SC World — Dell patches critical vulnerabilities in container storage modules
- Cybersecurity News — Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control
- SecurityOnline — Dell Patches Two CVSS 10 Flaws in Container Storage Modules