Dell has pushed out fixes for six critical flaws in its Container Storage Modules, the add-ons that wire enterprise storage into Kubernetes. Left open, they can hand an intruder both the cluster and the disk arrays behind it.
Two of the six earn a maximum 10.0. The first, CVE-2026-63688, sits in the csm-authorization-storage gRPC server, where a missing authentication check lets an unauthenticated remote party walk off with backend administrator credentials covering every registered array. The second, CVE-2026-63692, is the same class of oversight in the authorization proxy and tenant service, and it opens the door to a full authentication bypass for a network attacker.
The remaining four cluster near the top of the scale. Privilege handling is the weak point in the ContainerStorageModule Custom Resource reconciler, tracked as CVE-2026-67269 (9.9), where even a low-privilege user can reach root on cluster nodes by submitting a single resource. Hard-coded secrets account for two more: CVE-2026-54472 (9.8) buries credentials in the CSM Authorization module, enough to forge administrative tokens, while CVE-2026-61421 (9.8) exposes a signing key inside the karavi-authorization JWT component. Rounding out the set is CVE-2026-67273 (9.6), a template-injection bug that opens privilege escalation and RBAC tampering.
Dell says beating either 10.0 flaw amounts to a total bypass of the CSM authorization model, yielding administrative control over storage across five product families. The reconciler bug alone can leave every node in a cluster compromised.
Everything before version 1.17.0 is affected, and the fixes arrive in 1.18.0. Dell lists no mitigation beyond upgrading and is telling customers to rotate their JWT signing secrets.
