Dell Patches Six Critical Flaws in Container Storage Modules, Some Scoring a Perfect 10

 

Dell has shipped security fixes for six critical vulnerabilities in its Container Storage Modules (CSM) that could allow unauthenticated attackers to seize full administrative control over an organization's storage infrastructure and every node in a Kubernetes cluster. Four of the six flaws carry CVSS scores of 9.6 or higher, two of which hit the maximum possible rating of 10.0.

The bugs affect every version of CSM prior to 1.17.0, and Dell patched them in version 1.18.0. The company says no workarounds or interim mitigations exist, which means organizations running the affected software are down to one option: update now.

What CSM Does, and Why These Bugs Matter

Dell Container Storage Modules are Kubernetes-native extensions that manage persistent storage for containerized workloads across Dell's storage product families, including PowerFlex, PowerStore, PowerMax, PowerScale, and Unity XT. Because CSM sits at the intersection of storage credentials and cluster-level access controls, vulnerabilities in the platform carry a particularly high blast radius. An attacker who compromises CSM does not just gain access to data; they gain the ability to manipulate who can access what across every tenant connected to the system.

A closer look at the Six Vulnerabilities

The most severe of the six, CVE-2026-63688, scored a perfect 10.0. The flaw lives in the csm-authorization-storage gRPC server and requires no authentication to exploit. An attacker on the network can send requests directly to this endpoint and pull the backend administrator credentials for every storage array registered with the system. Dell's own advisory described it as enabling "a complete bypass of the csm-authorization security model," handing an attacker full administrative control over storage spanning all five supported Dell storage product families.

The second maximum-severity flaw, CVE-2026-63692, also a 10.0, targets the authorization proxy and tenant service. Like its counterpart, it requires zero credentials to exploit. A successful attack gives an adversary administrative control over the entire authorization service and the ability to access or manipulate storage resources across all connected tenants.

CVE-2026-67269 scored 9.9 and introduces a different threat model. It is a privilege escalation flaw in the ContainerStorageModule Custom Resource reconciler. A low-privilege attacker, not even a full admin, can submit a single maliciously crafted custom resource to the cluster and walk away with root-level access on every node in the environment. The attack surface is as small as one API call; the damage is cluster-wide.

Two of the remaining flaws center on hardcoded secrets. CVE-2026-54472 (CVSS 9.8) buries a static set of credentials inside the CSM Authorization module, allowing any remote attacker to forge cryptographically valid administrative tokens and seize control of the Authorization proxy. CVE-2026-61421 (also 9.8) compounds the problem: the JWT authentication component in karavi-authorization uses a hardcoded signing key. Because the signing secret is publicly available, anyone who locates it, something that is not especially difficult when code repositories are involved, can mint valid authentication tokens and claim administrative privileges without going through any login flow whatsoever.

The final flaw, CVE-2026-67273, scored 9.6 and is a template injection vulnerability. A low-privilege attacker with remote access can manipulate input fed through the template engine to escalate their own privileges, read sensitive information, and tamper with role-based access controls at the cluster scope. Dell's advisory noted that exploitation yields the ability to "create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls."

Context: Dell's Track Record With Exploited Flaws

This batch of CSM vulnerabilities does not arrive in isolation. Dell has faced repeated problems with critical infrastructure flaws being turned against real targets in the field. Earlier this year, researchers at Mandiant and Google's Threat Intelligence Group documented how CVE-2026-22769, a hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines carrying a CVSS score of 10.0, had been actively exploited as a zero-day since mid-2024 before Dell published a fix in February 2026. CISA added it to its Known Exploited Vulnerabilities catalog the following day. Years earlier, CVE-2021-21551, an access control flaw in Dell's dbutil driver, made the same list after evidence of active exploitation emerged in the wild.

The pattern here is consistent: attackers increasingly go after enterprise infrastructure components that security teams tend to treat as inherently trusted. Storage management platforms and low-level system utilities rarely face the same scrutiny as public-facing applications, and that blind spot has proven to be consequential.

What to Do

Dell is directing all customers to upgrade CSM to version 1.18.0 immediately.

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: