Protect.Computer
NEWS

Dell Patches Max-Severity Flaws in Container Storage Modules

· 1 min read · Got hacked Network safety
Dell Patches Max-Severity Flaws in Container Storage Modules

Dell has patched two maximum-severity vulnerabilities in the Container Storage Modules (CSM), the software that connects Dell enterprise storage arrays (PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT) to Kubernetes environments. Both bugs sit in the CSM Authorization module and are “missing authentication for critical functions” weaknesses, so no login is needed to exploit them. CVE-2026-63688 lets a remote attacker retrieve the storage backend administrator credentials for every registered array and bypass authorization to take full administrative control of the storage infrastructure. CVE-2026-63692, in the authorization proxy and tenant service, lets an attacker bypass authentication and gain complete administrative control of the authorization service, with potential access to storage resources across all tenants.

On the same day Dell fixed four more critical issues in CSM that remote attackers can also exploit without privileges: gaining root on cluster nodes (CVE-2026-67269), administrative access to the CSM Authorization proxy (CVE-2026-54472), forged authentication tokens that grant admin rights (CVE-2026-61421), and a Kubernetes access-control bypass that exposes cluster-wide read access to Secrets (CVE-2026-67273). Dell has not flagged any of the six as exploited in the wild, but it urges customers to upgrade at the earliest opportunity. Dell hardware has been a repeat target of state-backed groups, including a Chinese-linked cluster that abused a hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines earlier this year.

How to check if you’re affected

Affected products are Dell Container Storage Modules deployments, in particular those running the CSM Authorization module, on versions before 1.18.0.

  • Check the version: list your CSM and Authorization proxy deployments in each Kubernetes cluster and compare the installed version against 1.18.0, which contains the fixes.
  • Upgrade: move to CSM 1.18.0 or later, following the steps in Dell’s advisory DSA-2026-448.
  • Until you can patch: restrict network access to the CSM Authorization proxy and tenant service so only trusted cluster workloads can reach them, and plan to rotate storage array administrator credentials if the service was reachable from untrusted networks.

Sources

Related reading