Dell Patches Six Critical CSM Flaws, Two Rated a Perfect CVSS 10.0
Dell has disclosed and patched six critical vulnerabilities in its Container Storage Modules (CSM), the software layer that connects Dell's enterprise storage arrays to Kubernetes clusters. Two of the flaws, CVE-2026-63688 and CVE-2026-63692, received the maximum possible CVSS score of 10.0 and allow completely unauthenticated attackers to seize full administrative control over storage infrastructure and the authorization service that governs it. Dell published the fixes under advisory DSA-2026-448 on October 2, 2026, and is urging every CSM customer to upgrade to version 1.18.0 immediately, warning there are no workarounds for the affected components.
CSM extends the standard Container Storage Interface (CSI) drivers used by Kubernetes, adding enterprise features like replication, observability, and multi-tenant authorization for Dell's primary storage platforms: PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. Because CSM Authorization sits between Kubernetes tenants and the backend storage arrays, a compromise of that layer effectively hands an attacker the keys to every array it manages.
Incident Details
| Attribute | Value |
|---|---|
| Vendor | Dell Technologies |
| Product | Container Storage Modules (CSM) |
| Advisory ID | DSA-2026-448 |
| Publication Date | October 2, 2026 |
| Maximum CVSS Score | 10.0 (two flaws) |
| Vulnerable Versions | CSM Authorization, Operator, and CSI components prior to 1.18.0 |
| Fixed Version | 1.18.0 and later |
| Affected Platforms | PowerStore, PowerScale, PowerFlex, PowerMax, Unity XT |
| Attack Vector | Network, unauthenticated, low complexity |
| Exploitation Status | No known public exploitation or proof-of-concept at disclosure |
| Workaround Available | None — upgrade required |
How the Flaws Work
The Two Maximum-Severity Authorization Bypasses
CVE-2026-63688 (CVSS 10.0) is a missing-authentication flaw in the csm-authorization-storage gRPC server shipped with CSM Authorization version 2.4.0. Because the gRPC endpoint performs no authentication check, any network-reachable, unauthenticated attacker can query it directly to retrieve the administrator credentials for every storage array registered with CSM Authorization, then use those credentials to bypass the authorization layer entirely and take full administrative control of the storage backend.
CVE-2026-63692 (CVSS 10.0) sits in the authorization proxy and tenant service, the components CSM uses to route and authorize requests from individual Kubernetes tenants to shared storage resources. Dell's own advisory language is blunt about the blast radius: the bug "enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants." In a shared, multi-tenant cluster, that means one unauthenticated request can cross every tenant boundary CSM was designed to enforce.
Four Additional Critical-Severity Flaws
Dell disclosed four more critical bugs in the same advisory batch, all exploitable remotely without prior privileges:
- CVE-2026-67269 (CVSS 9.9) — a privilege-escalation flaw in CSM Operator version 1.12.0 that lets an attacker craft malicious Kubernetes resources to gain root on cluster nodes.
- CVE-2026-54472 (CVSS 9.8) — hard-coded credentials in CSM Authorization. Legacy documentation for the archived
karavi-authorizationcomponent referenced a sample JWT signing secret (the literal placeholder valuesupersecret) as an example. Deployments that copied the documented example and never rotated it can have authentication tokens forged by anyone who knows the default, granting admin access to the CSM Authorization proxy. - CVE-2026-61421 — a related authentication token-forgery flaw in the same archived
karavi-authorizationcomponent, also enabling attackers to mint valid admin tokens. - CVE-2026-67273 (CVSS 9.6) — a template-injection flaw in CSM Operator that bypasses Kubernetes RBAC controls, giving an attacker cluster-wide read access to Kubernetes Secrets, including the credential material stored for other services.
Attack Chain
None of the six issues require prior authentication, and several can be chained: an attacker who reaches the CSM Authorization gRPC endpoint over the network can pull storage admin credentials (CVE-2026-63688), pivot into the tenant/proxy layer to escalate across tenants (CVE-2026-63692), and — if the Operator is also unpatched — escalate to root on the underlying Kubernetes nodes (CVE-2026-67269) or harvest Secrets cluster-wide (CVE-2026-67273). Dell's advisory notes no evidence of active exploitation or public proof-of-concept code as of the October 2 disclosure, but the historical targeting of Dell storage and infrastructure products by groups such as Lazarus and UNC6201 means defenders should not treat the lack of in-the-wild activity as a reason to delay patching.
Impact Assessment
| Impact Area | Description |
|---|---|
| Storage Backend Compromise | Full administrative access to all arrays registered with CSM Authorization (PowerStore, PowerScale, PowerFlex, PowerMax, Unity XT) |
| Multi-Tenant Isolation | Tenant boundaries in shared Kubernetes/CSM deployments can be bypassed entirely, exposing one tenant's storage to another |
| Cluster Takeover | Chained exploitation can escalate to root on Kubernetes nodes running the CSM Operator |
| Secrets Exposure | Cluster-wide read access to Kubernetes Secrets, risking lateral movement into unrelated workloads and services |
| Data Integrity and Availability | Admin-level storage access enables data destruction, exfiltration, or ransomware-style encryption of enterprise storage volumes |
| Legacy Credential Risk | Organizations that never rotated the documented default JWT signing secret remain exposed even after other patches are applied |
Recommendations
For Dell CSM Administrators
- Upgrade all CSM Authorization, CSM Operator, and CSI driver components to version 1.18.0 or later immediately — Dell has confirmed there is no workaround short of upgrading.
- Treat this as emergency patching, not routine maintenance: two of the six flaws carry the maximum possible CVSS score and require no authentication to exploit.
- After upgrading, rotate the JWT signing secret used by CSM Authorization, especially if the deployment predates version 2.4.0 or was configured using older
karavi-authorizationdocumentation.
For Security Teams
- Audit CSM Authorization access logs for anomalous or unauthenticated requests to the
csm-authorization-storagegRPC endpoint prior to patching. - Review administrative token issuance and usage history for signs of forged or unexpected tokens tied to
CVE-2026-54472orCVE-2026-61421. - Inspect Kubernetes RBAC policies and Secret access logs for unauthorized modifications that may indicate exploitation of
CVE-2026-67273. - Restrict network reachability to CSM Authorization components to trusted management networks only, pending confirmation that all clusters are patched.
For Kubernetes Platform Owners
- Confirm which clusters run Dell CSM-integrated storage (PowerStore, PowerScale, PowerFlex, PowerMax, Unity XT) and prioritize those with multi-tenant workloads, since
CVE-2026-63692directly undermines tenant isolation. - Validate that the CSM Operator version in each cluster is
1.18.0or later before assuming any single component patch resolves the full exposure — the six CVEs span Authorization, Operator, and CSI layers independently. - Build CSM version verification into standard cluster health checks going forward, given the breadth of this disclosure.
Key Takeaways
- Dell patched six critical CSM vulnerabilities on October 2, 2026, under advisory DSA-2026-448; two (
CVE-2026-63688,CVE-2026-63692) scored a maximum CVSS 10.0. - All six flaws are remotely exploitable without authentication, and Dell has confirmed no workarounds exist — upgrading to CSM
1.18.0is the only remediation. - The flaws affect CSM integrations for PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT, covering the majority of Dell's enterprise storage lineup.
- A hard-coded/default JWT signing secret (
CVE-2026-54472) tied to legacykaravi-authorizationdocumentation means some environments stay exposed even after upgrading unless the secret is explicitly rotated. - Chained exploitation can escalate from stolen storage-admin credentials to root access on Kubernetes nodes and cluster-wide Secret exposure.
- No active exploitation or public proof-of-concept has been reported as of disclosure, but Dell's advisory cites historical targeting of its products by groups like Lazarus and UNC6201 as reason for urgency.
Sources
- Dell asks admins to patch max severity CSM flaws as soon as possible — BleepingComputer
- Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control — CybersecurityNews
- Critical Dell Container Storage Modules (CSM) Vulnerabilities Expose Kubernetes Environments to Remote Admin Compromise — Rescana