Overview
Dell has disclosed CVE-2026-54472, a critical hard-coded credentials vulnerability in the csm-docs component of Container Storage Modules (CSM), the toolkit that connects Kubernetes clusters to Dell storage platforms. Rated CVSS 9.8, the flaw lets an unauthenticated remote attacker retrieve sensitive information using a credential baked directly into the product.
This is one of five critical CSM vulnerabilities Dell patched together in advisory DSA-2026-448; see also CVE-2026-67269, CVE-2026-61421, CVE-2026-63688, and CVE-2026-63692. Note that several secondary writeups blur this issue together with CVE-2026-61421's JWT-forgery bug — Dell's own advisory scopes CVE-2026-54472 specifically to csm-docs and information disclosure, not token forgery.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-54472 |
| Severity | Critical (CVSS 9.8) |
| CWE | CWE-798 — Use of Hard-Coded Credentials |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network |
| Privileges Required | None |
| User Interaction | None |
| Impact | Information disclosure |
| Affected Component | csm-docs |
| Affected Versions | Before 1.18.0 |
| Fixed Version | 1.18.0 |
| Advisory | Dell DSA-2026-448 |
How It Works
The csm-docs component ships with a credential value embedded directly in its code or configuration rather than generated or injected at deployment time. Because the credential is identical across every CSM deployment that hasn't been patched, any attacker who knows or discovers the value — whether by analyzing publicly available CSM source/binaries or by probing the service — can authenticate as a trusted internal caller.
With that access, the attacker can query csm-docs for sensitive information that the component is otherwise meant to serve only to authorized, internal consumers — without ever needing valid cluster credentials, a service account token, or network-level trust beyond reaching the component.
Impact Assessment
Who Is At Risk
Any Kubernetes environment running CSM before 1.18.0 with the csm-docs component deployed and reachable, including:
- Clusters where csm-docs is exposed beyond the cluster-internal network
- Multi-tenant environments where any workload, regardless of namespace, can reach csm-docs over the cluster network
Potential Attack Chains
- Credential discovery — Attacker obtains the hard-coded credential value (from public source analysis, binary inspection, or prior disclosure)
- Unauthenticated access — Attacker uses the credential to authenticate to csm-docs as a trusted caller
- Data retrieval — Attacker queries csm-docs for information it exposes to authenticated callers, which may include configuration details, documentation on internal CSM wiring, or other sensitive metadata about the storage integration
- Reconnaissance for further attacks — Information gathered can inform follow-on exploitation of the other DSA-2026-448 vulnerabilities, particularly the missing-authentication issues in the Authorization gRPC server
Mitigation
Immediate Actions
- Upgrade CSM to 1.18.0 or later, which removes the hard-coded credential
- Restrict network reachability of csm-docs to cluster-internal sources only until patched
- Treat the hard-coded credential as compromised — there is no rotation path for a value baked into the binary short of upgrading
Detection Opportunities
- Review access logs for csm-docs for authentication attempts using generic or default-looking credential values
- Monitor for unexpected external network connections to the csm-docs service port
Defence-in-Depth
- Apply network policies that limit which workloads/namespaces can reach CSM's supporting components, not just the primary storage driver
- Audit all CSM components for other instances of embedded secrets as part of routine upgrade planning
Discovery & Disclosure
CVE-2026-54472 was published alongside Dell's advisory DSA-2026-448 on October 6, 2026. As of publication, there is no public proof-of-concept exploit and the flaw is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. There is no workaround short of upgrading to CSM 1.18.0.