Overview
Dell has disclosed CVE-2026-63692, a maximum-severity vulnerability in the authorization proxy and tenant service of CSM Authorization. Rated CVSS 10.0, the flaw lets an unauthenticated network attacker bypass authorization-proxy and tenant-service controls entirely, gaining administrative privileges across every tenant the Authorization service manages.
This is one of five critical CSM vulnerabilities Dell patched together in advisory DSA-2026-448; see also CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, and CVE-2026-63688.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-63692 |
| Severity | Critical (CVSS 10.0 — maximum) |
| CWE | CWE-306 — Missing Authentication for Critical Function |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Privileges Required | None |
| User Interaction | None |
| Impact | Cross-tenant administrative privilege escalation |
| Affected Component | Authorization proxy / tenant service |
| Affected Versions | Before 1.18.0 |
| Fixed Version | 1.18.0 |
| Advisory | Dell DSA-2026-448 |
How It Works
CSM Authorization's proxy and tenant service layer is responsible for enforcing which tenant a request belongs to and what that tenant is allowed to do — the boundary that keeps one team's storage access separate from another's in a shared cluster.
That enforcement layer fails to require authentication on requests reaching critical tenant-management functions. An unauthenticated network attacker who can reach the proxy/tenant service can issue requests that the service treats as legitimate administrative operations, without presenting any credential proving who they are or which tenant (if any) they represent. This lets the attacker assign themselves — or any identity they choose — administrative privileges spanning tenants that should otherwise be fully isolated from one another.
Impact Assessment
Who Is At Risk
Any Kubernetes environment running CSM Authorization before 1.18.0 where the authorization proxy/tenant service is network-reachable, particularly:
- Multi-tenant clusters that rely on CSM Authorization's tenant boundaries to keep separate teams or customers isolated from each other's storage access
- Environments where the proxy service is exposed beyond a tightly controlled internal network segment
Potential Attack Chains
- Network reachability — Attacker reaches the authorization proxy/tenant service, whether from inside the cluster or across an under-segmented network boundary
- Unauthenticated privilege request — Attacker issues tenant-management requests without any authentication
- Cross-tenant admin grant — The service processes the request as legitimate, granting the attacker administrative privileges across tenants
- Lateral compromise — With cross-tenant admin rights, the attacker can access or modify storage resources belonging to every tenant managed by the Authorization service, not just their own
Combined with CVE-2026-63688's unauthenticated credential exposure on the storage gRPC backend, an attacker reaching either component can unwind CSM Authorization's entire multi-tenant isolation model.
Mitigation
Immediate Actions
- Upgrade CSM Authorization to 1.18.0 or later immediately
- Audit tenant configurations post-upgrade for any unexpected administrative grants created before patching
- Restrict network reachability of the authorization proxy and tenant service to the minimum required internal callers while the upgrade is scheduled
Detection Opportunities
- Review Authorization service logs for tenant-management operations (role grants, tenant creation/modification) that lack an associated authenticated session
- Monitor for privilege grants spanning multiple tenants in a short time window, which may indicate automated exploitation
Defence-in-Depth
- Apply network segmentation so the authorization proxy and tenant service are reachable only from trusted, cluster-internal administrative paths
- Periodically audit tenant-to-privilege mappings independent of the Authorization service's own reporting, to catch drift introduced by this class of bug
Discovery & Disclosure
CVE-2026-63692 was published alongside Dell's advisory DSA-2026-448 on October 6, 2026. As of publication, there is no public proof-of-concept exploit and the flaw is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Given the maximum CVSS score and zero authentication requirement, treat patching as urgent regardless of confirmed in-the-wild exploitation.