At a glance:
-
Dell released Container Storage Modules (CSM) 1.18.0 on October 1, 2026, to address six critical vulnerabilities affecting how Kubernetes environments connect to and manage Dell storage infrastructure.
-
Two vulnerabilities rated with maximum CVSS scores allow an unauthenticated threat actor with network access to vulnerable services to gain administrative control over connected storage resources.
-
Identifying CSM deployments and upgrading versions earlier than 1.18.0 limits exposure to credential theft, authorization bypass, Kubernetes cluster compromise, and unauthorized access to stored data.
Threat summary
On October 1, 2026, Dell published security advisory DSA-2026-448 and released Container Storage Modules 1.18.0 to address six critical vulnerabilities. The two most severe flaws, CVE-2026-63688 and CVE-2026-63692, were rated with Common Vulnerability Scoring System (CVSS) scores of 10.0.
Dell Container Storage Modules (CSM) is a specialized platform used by organizations running Kubernetes or Red Hat OpenShift environments alongside Dell storage platforms such as PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. It's most commonly found in cloud infrastructure, platform engineering, and data center environments that support business-critical applications and shared storage resources.
CSM extends Kubernetes storage capabilities with features including authorization, replication, snapshots, resiliency, and observability. The vulnerabilities primarily affect the CSM Authorization module, which sits between Kubernetes workloads and storage systems to enforce access controls and tenant separation. Organizations using CSM often rely on it to manage access to shared storage resources that support multiple applications, business services, or tenants.
CVE-2026-63688
CVE-2026-63688 affects the csm-authorization-storage Google Remote Procedure Call (gRPC) server. The server provides the Authorization service with access to registered storage systems, but the vulnerable implementation fails to authenticate requests to critical functions.
A remote threat actor who can reach the service can retrieve administrator credentials for every registered storage array without an account or user interaction.
Those credentials provide a path to bypass the CSM authorization model and administer connected storage infrastructure across all five supported Dell storage product families.
CVE-2026-63692
CVE-2026-63692 is another missing-authentication vulnerability affecting the Authorization proxy and tenant service.
A remote, unauthenticated threat actor with network access to these components can bypass authentication and elevate privileges to the administrative level. In a multi-tenant environment, this access can extend to storage resources assigned to other tenants.
Exploitation depends on network access to the vulnerable CSM services rather than direct internet exposure, valid credentials, or user interaction.
Other fixed vulnerabilities
The update also fixes:
-
CVE-2026-67269
-
CVE-2026-54472
-
CVE-2026-61421
-
CVE-2026-67273
These vulnerabilities, which include improper privilege management, hard-coded credentials and cryptographic keys, and an authorization bypass, carry CVSS scores ranging from 9.6 to 9.9.
Depending on the vulnerability, successful exploitation can result in root access on Kubernetes cluster nodes, administrative access to the CSM Authorization proxy, forged authentication tokens, or cluster-wide access to Kubernetes Secrets.
Analysis
The highest-severity flaws, CVE-2026-63688 and CVE-2026-63692, affect components of the CSM Authorization service that handle access control for connected storage systems. Internet-facing deployments have a larger attack surface because external threat actors may be able to reach the vulnerable services directly.
However, internet exposure is not a prerequisite for exploitation. Internal-only deployments remain at risk if a threat actor gains a foothold in the environment, compromises a Kubernetes workload, accesses a connected network segment, or otherwise obtains network access to the affected CSM services.
CSM connects application workloads to centralized storage and operates with privileges that extend beyond an individual container. In a multi-tenant deployment, compromise of the Authorization service could cross tenant boundaries rather than remain limited to one namespace or workload.
The worst-case scenario could involve control of the storage layer combined with access to the Kubernetes environment. Depending on the systems and data connected to the affected deployment, a threat actor could obtain storage credentials, access sensitive data, alter or delete storage resources, forge administrative tokens, retrieve credentials stored as Kubernetes Secrets, or gain root access to cluster nodes.
How far that access extends beyond the confirmed vulnerable components depends on the deployment's network segmentation, secret management, storage permissions, and connected workloads.
Mitigations
-
Upgrade Dell CSM versions earlier than 1.18.0 to version 1.18.0 or later to correct these missing authentication, privilege management, hard-coded credential, cryptographic key, and authorization flaws.
-
Identify Kubernetes and OpenShift environments that use Dell CSM to establish the remediation scope. Common indicators include Dell Container Storage Interface (CSI) drivers for PowerStore, PowerScale, PowerFlex, PowerMax, or Unity XT storage systems, CSM namespaces and services such as csm-authorization and csm-replication, and Dell CSM operators deployed within Kubernetes or OpenShift clusters.
-
Limit network access to CSM Authorization services to approved cluster components and administrative systems to reduce the paths available for remote exploitation.
-
Review access to the csm-authorization-storage gRPC server, Authorization proxy, and tenant service to locate unintended exposure.
-
Monitor storage administration, authorization changes, token use, Kubernetes Secret access, and privileged activity on cluster nodes for signs of unauthorized access.
-
Rotate storage administrator credentials, authorization secrets, and signing keys where exposure is identified to remove access obtained before the update.