SECURITYCRITICALCVE-2026-63692

CVE-2026-63692: Dell CSM Authorization Proxy Missing Authentication Allows Cross-Tenant Admin Takeover

A missing authentication flaw in Dell CSM's authorization proxy lets unauthenticated attackers gain admin privileges across tenants.

Dylan H.

Security Team

October 7, 2026
4 min read
CVE-2026-63692: Dell CSM Authorization Proxy Missing Authentication Allows Cross-Tenant Admin Takeover

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Dell Container Storage Modules (CSM) Authorization before 1.18.0

Overview

Dell has disclosed CVE-2026-63692, a maximum-severity vulnerability in the authorization proxy and tenant service of CSM Authorization. Rated CVSS 10.0, the flaw lets an unauthenticated network attacker bypass authorization-proxy and tenant-service controls entirely, gaining administrative privileges across every tenant the Authorization service manages.

This is one of five critical CSM vulnerabilities Dell patched together in advisory DSA-2026-448; see also CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, and CVE-2026-63688.


Technical Details

FieldValue
CVE IDCVE-2026-63692
SeverityCritical (CVSS 10.0 — maximum)
CWECWE-306 — Missing Authentication for Critical Function
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack VectorNetwork
Privileges RequiredNone
User InteractionNone
ImpactCross-tenant administrative privilege escalation
Affected ComponentAuthorization proxy / tenant service
Affected VersionsBefore 1.18.0
Fixed Version1.18.0
AdvisoryDell DSA-2026-448

How It Works

CSM Authorization's proxy and tenant service layer is responsible for enforcing which tenant a request belongs to and what that tenant is allowed to do — the boundary that keeps one team's storage access separate from another's in a shared cluster.

That enforcement layer fails to require authentication on requests reaching critical tenant-management functions. An unauthenticated network attacker who can reach the proxy/tenant service can issue requests that the service treats as legitimate administrative operations, without presenting any credential proving who they are or which tenant (if any) they represent. This lets the attacker assign themselves — or any identity they choose — administrative privileges spanning tenants that should otherwise be fully isolated from one another.


Impact Assessment

Who Is At Risk

Any Kubernetes environment running CSM Authorization before 1.18.0 where the authorization proxy/tenant service is network-reachable, particularly:

  • Multi-tenant clusters that rely on CSM Authorization's tenant boundaries to keep separate teams or customers isolated from each other's storage access
  • Environments where the proxy service is exposed beyond a tightly controlled internal network segment

Potential Attack Chains

  1. Network reachability — Attacker reaches the authorization proxy/tenant service, whether from inside the cluster or across an under-segmented network boundary
  2. Unauthenticated privilege request — Attacker issues tenant-management requests without any authentication
  3. Cross-tenant admin grant — The service processes the request as legitimate, granting the attacker administrative privileges across tenants
  4. Lateral compromise — With cross-tenant admin rights, the attacker can access or modify storage resources belonging to every tenant managed by the Authorization service, not just their own

Combined with CVE-2026-63688's unauthenticated credential exposure on the storage gRPC backend, an attacker reaching either component can unwind CSM Authorization's entire multi-tenant isolation model.


Mitigation

Immediate Actions

  • Upgrade CSM Authorization to 1.18.0 or later immediately
  • Audit tenant configurations post-upgrade for any unexpected administrative grants created before patching
  • Restrict network reachability of the authorization proxy and tenant service to the minimum required internal callers while the upgrade is scheduled

Detection Opportunities

  • Review Authorization service logs for tenant-management operations (role grants, tenant creation/modification) that lack an associated authenticated session
  • Monitor for privilege grants spanning multiple tenants in a short time window, which may indicate automated exploitation

Defence-in-Depth

  • Apply network segmentation so the authorization proxy and tenant service are reachable only from trusted, cluster-internal administrative paths
  • Periodically audit tenant-to-privilege mappings independent of the Authorization service's own reporting, to catch drift introduced by this class of bug

Discovery & Disclosure

CVE-2026-63692 was published alongside Dell's advisory DSA-2026-448 on October 6, 2026. As of publication, there is no public proof-of-concept exploit and the flaw is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Given the maximum CVSS score and zero authentication requirement, treat patching as urgent regardless of confirmed in-the-wild exploitation.


References