Overview
Dell has disclosed CVE-2026-67269, a critical privilege-escalation flaw in the Container Storage Modules (CSM) Operator — the component that bridges Kubernetes clusters to Dell storage platforms such as PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. Rated CVSS 9.9, the bug lets a low-privileged user who can submit a Custom Resource escalate to root on cluster nodes.
This is one of five critical CSM vulnerabilities Dell patched together in advisory DSA-2026-448; see also CVE-2026-54472, CVE-2026-61421, CVE-2026-63688, and CVE-2026-63692.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-67269 |
| Severity | Critical (CVSS 9.9) |
| CWE | CWE-269 — Improper Privilege Management |
| CVSS Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Privileges Required | Low |
| User Interaction | None |
| Impact | Root-level code execution on cluster nodes |
| Affected Component | CSM Operator — ContainerStorageModule Custom Resource reconciler |
| Affected Versions | Before 1.18.0 |
| Fixed Version | 1.18.0 |
| Advisory | Dell DSA-2026-448 |
How It Works
The CSM Operator watches for ContainerStorageModule Custom Resources (CRs) and reconciles cluster state to match them — deploying storage driver pods, sidecars, and related workloads. The reconciler fails to adequately validate or constrain fields in attacker-submitted CRs.
A user holding only low-level Kubernetes privileges — enough to create or modify a ContainerStorageModule CR in a namespace they have access to — can craft a CR that causes the reconciler to deploy or modify workloads running with elevated node-level privileges. Because the reconciler itself typically runs with broad cluster permissions to manage storage components, this effectively lets the low-privileged submitter ride the Operator's own privileges to achieve root execution on underlying cluster nodes.
Impact Assessment
Who Is At Risk
Any Kubernetes cluster running CSM Operator before 1.18.0 where:
- Multiple tenants or teams have namespace-level access to submit Custom Resources
- RBAC does not tightly restrict who can create or edit
ContainerStorageModuleCRs - The cluster integrates with Dell PowerStore, PowerScale, PowerFlex, PowerMax, or Unity XT via CSM
Potential Attack Chains
- CR access — Attacker obtains namespace-scoped permissions sufficient to submit a
ContainerStorageModuleCR, e.g., as a tenant developer or compromised service account - Crafted reconciliation — Attacker submits a CR engineered to exploit reconciler validation gaps
- Privileged deployment — The Operator reconciles the CR into workloads running with node-level or root privileges
- Full node compromise — Attacker uses the resulting privileged context to pivot across the cluster, access secrets, or compromise other tenants' workloads
In multi-tenant clusters, this collapses the isolation boundary between tenants entirely — a single namespace-scoped actor can reach root on shared infrastructure.
Mitigation
Immediate Actions
- Upgrade CSM Operator to 1.18.0 or later without delay
- Audit Kubernetes RBAC to identify every principal capable of creating or modifying
ContainerStorageModuleCustom Resources, and restrict that set to trusted cluster administrators - Review existing CRs for signs of tampering or unusual configuration introduced before patching
Detection Opportunities
- Query the Kubernetes audit log for
ContainerStorageModuleCR create/update events originating from non-administrative accounts - Watch for unexpected privilege escalation in pods managed by the CSM Operator (unusual
hostPathmounts, privileged security contexts, or elevated service account bindings)
Defence-in-Depth
- Apply the principle of least privilege to all namespaces with storage-integration access — limit CR submission rights to platform teams only
- Use Kubernetes admission controllers (OPA/Gatekeeper, Kyverno) to enforce policy constraints on CSM-related Custom Resources independent of the Operator's own validation
- Segment multi-tenant clusters so that storage-integration components are managed in a dedicated, tightly-controlled namespace
Discovery & Disclosure
CVE-2026-67269 was published alongside Dell's advisory DSA-2026-448 on October 6, 2026. As of publication, there is no public proof-of-concept and the flaw is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. There is no workaround short of upgrading — Dell's advisory recommends patching to CSM 1.18.0 as the only remediation.