Skip to main content
CybersecurityVulnerability Management

Dell CSM Flaws Expose Kubernetes Nodes to Unauthenticated Admin Access

Storage equipment in a data center with surrounding infrastructure blurred.

"This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families," Dell said about CVE-2026-63688.

CVE-2026-63688: missing authentication that exposes storage backend credentials

Dell disclosed a missing-authentication vulnerability in the csm-authorization-storage gRPC server identified as CVE-2026-63688 (CVSS 10.0). According to the advisory, an unauthenticated remote attacker could exploit this flaw to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays. Dell characterized the vulnerability as a complete bypass of the csm-authorization security model, with administrative control extending across the vendor's five supported storage product families.

CVE-2026-63692, CVE-2026-54472 and CVE-2026-61421: proxy weaknesses and forged tokens

Three additional high-severity issues target authorization and token handling. CVE-2026-63692 (CVSS 10.0) is a missing-authentication vulnerability in the authorization proxy and tenant service that Dell says could allow an unauthenticated network attacker to bypass authentication controls and gain administrative-level privileges, enabling access to or manipulation of storage resources across all tenants.

CVE-2026-54472 (CVSS 9.8) involves the use of hard-coded credentials in the CSM Authorization module; Dell warns that a remote unauthenticated attacker could exploit this to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy. Relatedly, CVE-2026-61421 (CVSS 9.8) describes a hard-coded cryptographic key in the JWT authentication component of karavi-authorization that an attacker with knowledge of the publicly available signing secret could use to forge authentication tokens and gain administrative privileges. Dell is recommending that customers apply the updates and rotate any JWT signing secrets.

CVE-2026-67269 and CVE-2026-67273: Kubernetes node root, secrets access and RBAC tampering

The advisory also details flaws that affect cluster behavior and Kubernetes controls. CVE-2026-67269 (CVSS 9.9) is an improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler; Dell says a low-privilege remote attacker could exploit it to escalate privileges and gain root-level access on cluster nodes, enabling compromise of all nodes in a Kubernetes cluster through a single custom resource submission.

CVE-2026-67273 (CVSS 9.6) is an improper neutralization of special elements used in a template engine. Dell's advisory states that a low-privilege attacker with remote access could exploit this to escalate privileges, access sensitive information, and carry out unauthorized RBAC tampering. Dell adds that "Successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls."

CSM versions, remediation, and the absence of mitigations

Dell said the flaws affect all versions of Container Storage Modules (CSM) prior to 1.17.0 and that they have been addressed in CSM 1.18.0. The vendor reported there are no workarounds or mitigations other than updating to the latest version. The advisory singles out two concrete operational steps: apply the updated CSM release and rotate JWT signing secrets where applicable.

The notice also referenced prior Dell product vulnerabilities — CVE-2021-21551 and CVE-2026-22769 — stating those had come under active exploitation in recent years, underscoring Dell's admonition that customers "apply the necessary fixes for optimal protection."

What this means for technologists and security teams, affected enterprises and procurement leaders, and adversaries and threat actors

  • Technologists and security teams: Patch to CSM 1.18.0 without delay and rotate JWT signing secrets as Dell recommends; the advisory notes no viable workarounds, so updating is the primary remediation.
  • Affected enterprises and procurement leaders: Inventory CSM deployments to determine which instances run versions prior to 1.17.0, prioritize upgrades across tenants and arrays, and validate that administrative credentials and token-signing secrets have been rotated after patching.
  • Adversaries and threat actors: The described failures include unauthenticated paths to administrator credentials and forged token capabilities, and the advisory explicitly connects those capabilities to administrative control across tenants and cluster-wide access to Kubernetes Secrets — conditions that adversaries could exploit if systems remain unpatched.

These vulnerabilities collectively span authentication bypasses, hard-coded secrets, and privilege escalation that affect both storage management layers and underlying Kubernetes clusters. With fixes consolidated in CSM 1.18.0 and no alternate mitigations available, Dell's advisory leaves a clear operational demand: update the software and rotate signing secrets to close attack paths that the vendor warns can yield full administrative control across storage families and cluster-wide access to secrets.

Original story