Overview
Dell has disclosed CVE-2026-63688, a maximum-severity vulnerability in the csm-authorization-storage gRPC server, a backend component of CSM Authorization. Rated CVSS 10.0, the flaw lets an unauthenticated remote attacker retrieve administrator credentials for every Dell storage array registered with the Authorization service — a complete bypass of the csm-authorization security model.
This is one of five critical CSM vulnerabilities Dell patched together in advisory DSA-2026-448; see also CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, and CVE-2026-63692.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-63688 |
| Severity | Critical (CVSS 10.0 — maximum) |
| CWE | CWE-306 — Missing Authentication for Critical Function |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Privileges Required | None |
| User Interaction | None |
| Impact | Full retrieval of storage array administrator credentials |
| Affected Component | csm-authorization-storage gRPC server |
| Affected Versions | Before 1.18.0 |
| Fixed Version | 1.18.0 |
| Advisory | Dell DSA-2026-448 |
How It Works
CSM Authorization centralizes credentials for every Dell storage array (PowerStore, PowerScale, PowerFlex, PowerMax, Unity XT) that a Kubernetes cluster is permitted to use, so individual tenants never need direct admin access to the underlying arrays. The csm-authorization-storage gRPC server is the backend service that holds and serves those registered-storage-system credentials to the rest of the Authorization stack.
The gRPC server performs no authentication check on incoming requests. Any network client capable of reaching the gRPC endpoint can call its methods directly and retrieve the administrator credentials for all storage systems registered with the Authorization service — without presenting a token, a valid JWT, or any other proof of identity.
Impact Assessment
Who Is At Risk
Any Kubernetes environment running CSM Authorization before 1.18.0 where the csm-authorization-storage gRPC server is reachable over the network, including:
- Clusters where pod-to-pod network policy does not restrict access to Authorization's internal gRPC endpoints
- Multi-tenant clusters where any workload, regardless of trust level, shares a network path to the Authorization namespace
Potential Attack Chains
- Network reachability — Attacker (an internal workload, compromised pod, or anyone with cluster network access) reaches the gRPC endpoint
- Unauthenticated credential retrieval — Attacker calls the gRPC server directly and retrieves administrator credentials for every registered storage array
- Direct array access — Attacker uses the stolen credentials to authenticate directly to the underlying Dell storage systems, bypassing CSM Authorization and Kubernetes entirely
- Data and infrastructure compromise — With storage-array admin credentials, the attacker can read, modify, or destroy data across every volume and system the array manages — far beyond anything exposed to a single tenant
This is the most severe of the five DSA-2026-448 vulnerabilities: it doesn't just escalate privileges inside Kubernetes, it hands over the underlying storage infrastructure's own admin credentials, independent of any Kubernetes-layer protections.
Mitigation
Immediate Actions
- Upgrade CSM Authorization to 1.18.0 or later immediately — this is the only remediation
- Rotate all storage array administrator credentials registered with CSM Authorization, since any unpatched deployment should be treated as having potentially exposed them already
- Restrict network reachability of the csm-authorization-storage gRPC endpoint to the minimum required internal callers while patching is scheduled
Detection Opportunities
- Review network flow logs for unexpected traffic to the csm-authorization-storage gRPC port from outside the Authorization service's expected caller set
- Audit storage array access logs for administrative logins that don't correspond to known CSM Authorization service activity
Defence-in-Depth
- Apply strict network policies (NetworkPolicy, service mesh mTLS) around all Authorization backend components, not just the user-facing API
- Treat storage-array admin credentials as a tier-0 secret requiring the same rotation discipline as domain admin or cloud root credentials
Discovery & Disclosure
CVE-2026-63688 was published alongside Dell's advisory DSA-2026-448 on October 6, 2026. As of publication, there is no public proof-of-concept exploit and the flaw is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog — but given the maximum CVSS score, zero authentication requirement, and the severity of what's exposed, this should be treated as an emergency patch regardless of confirmed in-the-wild activity.