SECURITYCRITICALCVE-2026-54472

CVE-2026-54472: Hard-Coded Credentials in Dell CSM Docs Component Expose Sensitive Data

A hard-coded credential in Dell Container Storage Modules' csm-docs component lets unauthenticated attackers read sensitive data.

Dylan H.

Security Team

October 7, 2026
4 min read
CVE-2026-54472: Hard-Coded Credentials in Dell CSM Docs Component Expose Sensitive Data

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Dell Container Storage Modules (CSM) before 1.18.0

Overview

Dell has disclosed CVE-2026-54472, a critical hard-coded credentials vulnerability in the csm-docs component of Container Storage Modules (CSM), the toolkit that connects Kubernetes clusters to Dell storage platforms. Rated CVSS 9.8, the flaw lets an unauthenticated remote attacker retrieve sensitive information using a credential baked directly into the product.

This is one of five critical CSM vulnerabilities Dell patched together in advisory DSA-2026-448; see also CVE-2026-67269, CVE-2026-61421, CVE-2026-63688, and CVE-2026-63692. Note that several secondary writeups blur this issue together with CVE-2026-61421's JWT-forgery bug — Dell's own advisory scopes CVE-2026-54472 specifically to csm-docs and information disclosure, not token forgery.


Technical Details

FieldValue
CVE IDCVE-2026-54472
SeverityCritical (CVSS 9.8)
CWECWE-798 — Use of Hard-Coded Credentials
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNetwork
Privileges RequiredNone
User InteractionNone
ImpactInformation disclosure
Affected Componentcsm-docs
Affected VersionsBefore 1.18.0
Fixed Version1.18.0
AdvisoryDell DSA-2026-448

How It Works

The csm-docs component ships with a credential value embedded directly in its code or configuration rather than generated or injected at deployment time. Because the credential is identical across every CSM deployment that hasn't been patched, any attacker who knows or discovers the value — whether by analyzing publicly available CSM source/binaries or by probing the service — can authenticate as a trusted internal caller.

With that access, the attacker can query csm-docs for sensitive information that the component is otherwise meant to serve only to authorized, internal consumers — without ever needing valid cluster credentials, a service account token, or network-level trust beyond reaching the component.


Impact Assessment

Who Is At Risk

Any Kubernetes environment running CSM before 1.18.0 with the csm-docs component deployed and reachable, including:

  • Clusters where csm-docs is exposed beyond the cluster-internal network
  • Multi-tenant environments where any workload, regardless of namespace, can reach csm-docs over the cluster network

Potential Attack Chains

  1. Credential discovery — Attacker obtains the hard-coded credential value (from public source analysis, binary inspection, or prior disclosure)
  2. Unauthenticated access — Attacker uses the credential to authenticate to csm-docs as a trusted caller
  3. Data retrieval — Attacker queries csm-docs for information it exposes to authenticated callers, which may include configuration details, documentation on internal CSM wiring, or other sensitive metadata about the storage integration
  4. Reconnaissance for further attacks — Information gathered can inform follow-on exploitation of the other DSA-2026-448 vulnerabilities, particularly the missing-authentication issues in the Authorization gRPC server

Mitigation

Immediate Actions

  • Upgrade CSM to 1.18.0 or later, which removes the hard-coded credential
  • Restrict network reachability of csm-docs to cluster-internal sources only until patched
  • Treat the hard-coded credential as compromised — there is no rotation path for a value baked into the binary short of upgrading

Detection Opportunities

  • Review access logs for csm-docs for authentication attempts using generic or default-looking credential values
  • Monitor for unexpected external network connections to the csm-docs service port

Defence-in-Depth

  • Apply network policies that limit which workloads/namespaces can reach CSM's supporting components, not just the primary storage driver
  • Audit all CSM components for other instances of embedded secrets as part of routine upgrade planning

Discovery & Disclosure

CVE-2026-54472 was published alongside Dell's advisory DSA-2026-448 on October 6, 2026. As of publication, there is no public proof-of-concept exploit and the flaw is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. There is no workaround short of upgrading to CSM 1.18.0.


References