
Dell CSM Flaws Patched After Admin Takeover Risk
Dell fixed six critical Dell CSM flaws that allowed unauthenticated admin access, forged tokens, and root-level control of Kubernetes nodes. Update to 1.18.0.
Dell has shipped fixes for six critical Dell CSM flaws in its Container Storage Modules, the software layer that connects Kubernetes storage to Dell storage arrays. The vulnerabilities allow an unauthenticated remote attacker to bypass login controls, forge administrator tokens, and take root-level control of Kubernetes cluster nodes. Dell said all versions of CSM before 1.17.0 are affected, and the fixes are available in version 1.18.0. There are no workarounds or mitigations other than updating.
The six flaws, listed by Dell with their CVSS severity scores, cover several parts of the CSM authorization system. CVE-2026-63688 has a CVSS score of 10.0 and is a missing authentication problem in the csm-authorization-storage gRPC server; an unauthenticated remote attacker can read the administrator credentials for every registered storage array. CVE-2026-63692, also 10.0, is a missing authentication issue in the authorization proxy and tenant service that lets an unauthenticated network attacker bypass authentication and gain administrative privileges. CVE-2026-67269 has a CVSS score of 9.9 and is an improper privilege management flaw in the ContainerStorageModule custom resource reconciler; a low-privilege remote attacker can escalate to root access on cluster nodes. CVE-2026-54472 has a score of 9.8 and uses hard-coded credentials in the CSM Authorization module, which allows a remote unauthenticated attacker to forge cryptographically valid administrator tokens. CVE-2026-61421, also 9.8, is a hard-coded cryptographic key in the JWT authentication component of karavi-authorization, letting an attacker who knows the publicly available signing secret forge authentication tokens and gain administrative privileges. CVE-2026-67273 has a CVSS score of 9.6 and is an improper neutralization of special elements used in a template engine; a low-privilege attacker with remote access can escalate privileges, read sensitive information, and tamper with RBAC settings.
Dell said CVE-2026-63688 is critical because it enables a complete bypass of the csm-authorization security model, giving an attacker full administrative control over the storage infrastructure across all five supported Dell storage product families. For CVE-2026-63692, Dell noted that successful exploitation could give an unauthenticated attacker complete administrative control over the authorization service and allow them to access or manipulate storage resources across all tenants. Dell also said an attacker can use CVE-2026-67269 to compromise all nodes in a Kubernetes cluster through a single custom resource submission. CVE-2026-54472 can be used to sidestep authentication controls for the CSM Authorization proxy and enable unauthorized management of storage access policies across all connected tenants. For CVE-2026-67273, Dell's advisory states that successful exploitation grants cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls.
The update closes all six flaws in CSM 1.18.0, and Dell is recommending that customers apply it and rotate any JWT signing secrets after updating. The company stated that there are no workarounds or mitigations other than updating to the latest version. The risk is not theoretical: Dell noted that earlier vulnerabilities in Dell products, CVE-2021-21551 and CVE-2026-22769, have come under active exploitation in recent years, which makes quick patching important. Organizations running Kubernetes clusters or storage arrays connected to Dell CSM should treat this as an urgent update.
For website owners, hosting providers, and IT teams, the flaws matter because Kubernetes commonly sits behind modern websites, application back ends, and managed hosting platforms. If an attacker takes over a Kubernetes node, they may reach customer data, secrets, and the workloads that serve pages and APIs. The fact that no workaround exists makes the upgrade the only safe option. Teams managing such infrastructure may find a security-first infrastructure partner like AEU-I useful for reviewing authentication controls and patch processes before an incident happens.
How to Protect Yourself
- If your organization uses Dell Container Storage Modules, update to version 1.18.0 without delay.
- After updating, change the secret signing keys used for login tokens, as Dell recommends, because old keys may still let attackers in.
- If you are not the person who manages your storage platform, ask your IT team or hosting provider to confirm the Dell CSM patch has been applied.
- Keep an inventory of the storage and container systems your website depends on, and subscribe to vendor security alerts so you learn about patches quickly.
- If you run a Kubernetes cluster yourself, review who can submit custom resources and remove any unnecessary accounts or permissions.
Vulnerabilities & Fixes
- CVE-2026-54472 Use of hard-coded credentials in the CSM Authorization module; fixed in CSM 1.18.0. View the fix & details →
- CVE-2026-61421 Use of hard-coded cryptographic key in the JWT authentication component of karavi-authorization; fixed in CSM 1.18.0. View the fix & details →
- CVE-2026-63688 Missing authentication in the csm-authorization-storage gRPC server; fixed in CSM 1.18.0. View the fix & details →
- CVE-2026-63692 Missing authentication in the authorization proxy and tenant service; fixed in CSM 1.18.0. View the fix & details →
- CVE-2026-67269 Improper privilege management in the ContainerStorageModule custom resource reconciler; fixed in CSM 1.18.0. View the fix & details →
- CVE-2026-67273 Improper neutralization of special elements in a template engine; fixed in CSM 1.18.0. View the fix & details →
Terms Explained
- Container Storage Modules (CSM) Software from Dell that lets Kubernetes manage storage on Dell storage arrays.
- Kubernetes A system that runs and manages containerized applications across many computers, often used for websites and cloud services.
- CVSS A standard scoring system that rates how severe a security vulnerability is, from 0 to 10.
- Authentication The process of proving who you are before a system lets you in, like a login step.
- RBAC A way to limit what each user can do based on the role they are assigned.
- JWT A small piece of data that proves a user or service is allowed to access something.
- gRPC A method that software uses to talk to other software quickly, often inside data centers.