Dell patches two CVSS 10 flaws in Container Storage Modules for Kubernetes
Dell urges customers to upgrade Container Storage Modules to 1.18.0 after fixing critical flaws that can give unauthenticated attackers admin control over connected storage arrays.
At a glance
- CVE-2026-63688 and CVE-2026-63692 are rated CVSS 10 and allow unauthenticated takeover of the CSM authorization service
- The advisory DSA-2026-448 also fixes flaws enabling root access on cluster nodes and cluster-wide reading of Kubernetes Secrets
- No exploitation in the wild has been reported, and no workarounds exist
- Dell recommends upgrading to CSM 1.18.0 or later at the earliest opportunity
Dell has released security updates for its Container Storage Modules (CSM), the software that connects Kubernetes clusters to Dell enterprise storage platforms, fixing two maximum-severity vulnerabilities that could give unauthenticated remote attackers full administrative control over the storage infrastructure. According to BleepingComputer, the company is asking administrators to upgrade "at the earliest opportunity." The flaws matter because the CSM authorization service typically holds administrator credentials for every connected storage array.
What happened
Dell published advisory DSA-2026-448 on October 2, addressing a batch of vulnerabilities in CSM. BleepingComputer reports that the advisory lists 13 Dell-specific CVEs alongside a number of flaws in third-party Go libraries used by the product. Two of the Dell-specific issues, CVE-2026-63688 and CVE-2026-63692, carry a CVSS score of 10.0, according to SecurityOnline.
Neither BleepingComputer nor SecurityOnline reports any exploitation in the wild at this time. BleepingComputer notes, however, that other Dell vulnerabilities have been weaponized by state-sponsored actors in the past.
Technical details
According to SecurityOnline, CVE-2026-63688 resides in the csm-authorization-storage gRPC server. A remote attacker without credentials could obtain the storage backend administrator credentials for all registered arrays and bypass authorization, gaining full control over storage spanning the PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT product families. CVE-2026-63692 affects the authorization proxy and tenant service and, as Dell describes it, could allow an attacker to take complete administrative control of the authorization service and manipulate storage resources across all tenants.
The advisory also covers several other critical issues, SecurityOnline reports:
CVE-2026-67269(CVSS 9.9) in the CSM Operator, which could let a low-privileged user gain root access on cluster nodes.CVE-2026-67273(CVSS 9.6), which could grant cluster-wide read access to Kubernetes Secrets.CVE-2026-54472(CVSS 9.8), hard-coded credentials that could be used to forge valid admin tokens.CVE-2026-61421, a sample JWT signing secret published in setup guides for the archivedkaravi-authorizationproject, which is a risk for organizations that adopted the sample and never rotated it.
Who is affected
Organizations that use Dell CSM, and in particular its Authorization module, to connect Kubernetes workloads to Dell storage arrays are affected. Because the authorization service stores array administrator credentials, a compromise could extend well beyond individual applications to the underlying storage systems.
What to do
Dell's fixed release is CSM 1.18.0 or later, and SecurityOnline reports that there are no workarounds. Beyond upgrading, the outlet recommends rotating all JWT signing secrets, replacing storage backend administrator passwords stored in CSM, retiring any remaining karavi-authorization deployments, which are no longer maintained, restricting network access to the CSM authorization services and reviewing RBAC roles for unauthorized changes.
Related CVEs
Sources
- Dell asks admins to patch max severity CSM flaws as soon as possible — BleepingComputer
- Dell Patches Two CVSS 10 Flaws in Container Storage Modules — SecurityOnline
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



