SECURITYCRITICALCVE-2026-67269

CVE-2026-67269: Dell CSM Operator Flaw Lets Low-Privileged Users Escalate to Cluster Node Root

A Dell Container Storage Modules Operator flaw lets low-privileged Kubernetes users escalate to root via a crafted Custom Resource.

Dylan H.

Security Team

October 7, 2026
4 min read
CVE-2026-67269: Dell CSM Operator Flaw Lets Low-Privileged Users Escalate to Cluster Node Root

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Dell Container Storage Modules (CSM) Operator before 1.18.0

Overview

Dell has disclosed CVE-2026-67269, a critical privilege-escalation flaw in the Container Storage Modules (CSM) Operator — the component that bridges Kubernetes clusters to Dell storage platforms such as PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. Rated CVSS 9.9, the bug lets a low-privileged user who can submit a Custom Resource escalate to root on cluster nodes.

This is one of five critical CSM vulnerabilities Dell patched together in advisory DSA-2026-448; see also CVE-2026-54472, CVE-2026-61421, CVE-2026-63688, and CVE-2026-63692.


Technical Details

FieldValue
CVE IDCVE-2026-67269
SeverityCritical (CVSS 9.9)
CWECWE-269 — Improper Privilege Management
CVSS VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack VectorNetwork
Privileges RequiredLow
User InteractionNone
ImpactRoot-level code execution on cluster nodes
Affected ComponentCSM Operator — ContainerStorageModule Custom Resource reconciler
Affected VersionsBefore 1.18.0
Fixed Version1.18.0
AdvisoryDell DSA-2026-448

How It Works

The CSM Operator watches for ContainerStorageModule Custom Resources (CRs) and reconciles cluster state to match them — deploying storage driver pods, sidecars, and related workloads. The reconciler fails to adequately validate or constrain fields in attacker-submitted CRs.

A user holding only low-level Kubernetes privileges — enough to create or modify a ContainerStorageModule CR in a namespace they have access to — can craft a CR that causes the reconciler to deploy or modify workloads running with elevated node-level privileges. Because the reconciler itself typically runs with broad cluster permissions to manage storage components, this effectively lets the low-privileged submitter ride the Operator's own privileges to achieve root execution on underlying cluster nodes.


Impact Assessment

Who Is At Risk

Any Kubernetes cluster running CSM Operator before 1.18.0 where:

  • Multiple tenants or teams have namespace-level access to submit Custom Resources
  • RBAC does not tightly restrict who can create or edit ContainerStorageModule CRs
  • The cluster integrates with Dell PowerStore, PowerScale, PowerFlex, PowerMax, or Unity XT via CSM

Potential Attack Chains

  1. CR access — Attacker obtains namespace-scoped permissions sufficient to submit a ContainerStorageModule CR, e.g., as a tenant developer or compromised service account
  2. Crafted reconciliation — Attacker submits a CR engineered to exploit reconciler validation gaps
  3. Privileged deployment — The Operator reconciles the CR into workloads running with node-level or root privileges
  4. Full node compromise — Attacker uses the resulting privileged context to pivot across the cluster, access secrets, or compromise other tenants' workloads

In multi-tenant clusters, this collapses the isolation boundary between tenants entirely — a single namespace-scoped actor can reach root on shared infrastructure.


Mitigation

Immediate Actions

  • Upgrade CSM Operator to 1.18.0 or later without delay
  • Audit Kubernetes RBAC to identify every principal capable of creating or modifying ContainerStorageModule Custom Resources, and restrict that set to trusted cluster administrators
  • Review existing CRs for signs of tampering or unusual configuration introduced before patching

Detection Opportunities

  • Query the Kubernetes audit log for ContainerStorageModule CR create/update events originating from non-administrative accounts
  • Watch for unexpected privilege escalation in pods managed by the CSM Operator (unusual hostPath mounts, privileged security contexts, or elevated service account bindings)

Defence-in-Depth

  • Apply the principle of least privilege to all namespaces with storage-integration access — limit CR submission rights to platform teams only
  • Use Kubernetes admission controllers (OPA/Gatekeeper, Kyverno) to enforce policy constraints on CSM-related Custom Resources independent of the Operator's own validation
  • Segment multi-tenant clusters so that storage-integration components are managed in a dedicated, tightly-controlled namespace

Discovery & Disclosure

CVE-2026-67269 was published alongside Dell's advisory DSA-2026-448 on October 6, 2026. As of publication, there is no public proof-of-concept and the flaw is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. There is no workaround short of upgrading — Dell's advisory recommends patching to CSM 1.18.0 as the only remediation.


References