Six flaws in Dell’s storage modules put clusters at risk

Two of the bugs earn a perfect 10.0 score, and Dell says there is no workaround short of upgrading.

CSBadmin
2 Min Read

Dell has pushed out fixes for six critical flaws in its Container Storage Modules, the add-ons that wire enterprise storage into Kubernetes. Left open, they can hand an intruder both the cluster and the disk arrays behind it.

Two of the six earn a maximum 10.0. The first, CVE-2026-63688, sits in the csm-authorization-storage gRPC server, where a missing authentication check lets an unauthenticated remote party walk off with backend administrator credentials covering every registered array. The second, CVE-2026-63692, is the same class of oversight in the authorization proxy and tenant service, and it opens the door to a full authentication bypass for a network attacker.

The remaining four cluster near the top of the scale. Privilege handling is the weak point in the ContainerStorageModule Custom Resource reconciler, tracked as CVE-2026-67269 (9.9), where even a low-privilege user can reach root on cluster nodes by submitting a single resource. Hard-coded secrets account for two more: CVE-2026-54472 (9.8) buries credentials in the CSM Authorization module, enough to forge administrative tokens, while CVE-2026-61421 (9.8) exposes a signing key inside the karavi-authorization JWT component. Rounding out the set is CVE-2026-67273 (9.6), a template-injection bug that opens privilege escalation and RBAC tampering.

Dell says beating either 10.0 flaw amounts to a total bypass of the CSM authorization model, yielding administrative control over storage across five product families. The reconciler bug alone can leave every node in a cluster compromised.

Everything before version 1.17.0 is affected, and the fixes arrive in 1.18.0. Dell lists no mitigation beyond upgrading and is telling customers to rotate their JWT signing secrets.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.