Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control

October 2, 2026

Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Modules, including flaws that could allow unauthenticated remote attackers to take full administrative control of affected storage environments.

Organizations using vulnerable Dell CSM deployments should upgrade immediately, as Dell stated that no workarounds or mitigations are available.

The advisory affects Dell Container Storage Modules versions before 1.17.0, with fixes available in 1.18.0 and later, covering CSM Authorization, CSM Operator, CSI components, and third-party Go libraries.

The most severe vulnerabilities are CVE-2026-63688 and CVE-2026-63692, both assigned a CVSS score of 10.0. CVE-2026-63688 is a missing authentication flaw in the csm-authorization-storage gRPC server in CSM Authorization version 2.4.0.

An unauthenticated attacker could exploit the flaw to access administrator credentials for all registered storage arrays, potentially gaining control across Dell’s five supported storage product families.

Access to backend administrator credentials could enable an attacker to change storage configurations, access sensitive data, disrupt workloads, or create persistent access paths within the environment.

Critical Dell Container Storage Flaws

CVE-2026-63692 also affects CSM Authorization version 2.4.0. The vulnerability exists in the authorization proxy and tenant service, where critical functions can be reached without proper authentication.

Successful exploitation could allow a network-based attacker to bypass authentication controls and elevate privileges to the administrative level. This could expose and enable manipulation of storage resources across all tenants.

Another critical issue, CVE-2026-54472, is a hard-coded credentials vulnerability in CSM Authorization. The flaw could allow an unauthenticated remote attacker to forge cryptographically valid administrative JSON Web Tokens and gain administrator access to the CSM Authorization proxy.

Dell rated the flaw CVSS 9.8 and advised rotating JWT signing secrets after updating, the advisory also addresses CVE-2026-61421 in the archived karavi-authorization component.

Dell said older documentation used the JWT signing secret “supersecret” alongside a real token example. Organizations that deployed karavi-authorization using this documented value and never changed the signing secret may remain exposed to forged-token attacks and administrative takeover.

CVE-2026-67269 in Dell CSM Operator 1.12.0 could let low-privileged remote users gain root access to Kubernetes nodes via a malicious ContainerStorageModule resource, Dell rated it 9.9 due to potential cluster-wide compromise.

CVE-2026-67273, rated 9.6, could permit a low-privileged attacker to access Kubernetes Secrets and create cluster-scoped RBAC resources through template-engine injection. Such access could effectively bypass intended Kubernetes permissions and allow broad control of cluster resources.

Other flaws include improper certificate validation, missing authorization in the Dell CSI Driver for PowerMax, sensitive-information disclosure through logs, and flaws affecting CSI drivers for PowerFlex, PowerMax, and PowerStore.

The update also addresses vulnerabilities in third-party Go components, including golang.org/x/crypto, golang.org/x/net, golang-jwt/jwt, and protobuf.

Dell recommends upgrading all affected Container Storage Modules deployments to version 1.18.0 or later at the earliest opportunity. Security teams should also rotate JWT secrets, review CSM Authorization access logs, audit administrative token usage, and check Kubernetes RBAC policies and custom resources for unauthorized changes.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Original article can be found here