Skip to main content
CybersecurityVulnerability Management

Dell Urges Admins to Patch CSM Flaws Exploiting Authorization Controls

Storage administrator's workstation with laptop and blurred screen in a data center environment.
"This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants," Dell warned.

The vulnerabilities: CVE-2026-63688 and CVE-2026-63692

Dell disclosed two maximum-severity flaws in its Container Storage Modules (CSM) authorization security module that stem from "missing authentication for critical functions." The first, tracked as CVE-2026-63688, permits unauthenticated remote attackers to access storage backend administrator credentials for all registered storage arrays and to bypass authorization controls to gain full administrative control over the storage infrastructure. The second, CVE-2026-63692, is present in the authorization proxy and tenant service and likewise allows threat actors to gain administrative privileges by bypassing authentication controls.

In plain terms from Dell's advisory: the missing authentication can give an unauthenticated attacker the keys — administrator credentials and authorization bypasses — needed to control the authorization service and, by extension, manipulate storage resources across tenants.

Four additional critical CSM flaws patched the same day

Dell also released fixes for four more critical CSM vulnerabilities on the same day. Each, according to the advisory, can be exploited by remote attackers without privileges:

  • CVE-2026-67269 — attackers can gain root on cluster nodes.
  • CVE-2026-54472 — attackers can gain administrative access to the CSM Authorization proxy.
  • CVE-2026-61421 — attackers can forge authentication tokens to gain administrative privileges.
  • CVE-2026-67273 — attackers can bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets.

Dell's mitigation is prescriptive and straightforward: update container storage modules to version 1.18.0 or later, which patches these flaws. "Dell recommends customers to upgrade at the earliest opportunity," the advisory says.

Dell platforms affected and where CSM sits

CSM is the bridge between Dell's enterprise storage arrays and Kubernetes environments. The module supports Dell's primary storage platforms — PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT — and extends the standard Container Storage Interface (CSI) drivers for Kubernetes. The vulnerabilities therefore affect environments where those arrays are registered and managed through CSM in Kubernetes clusters.

Historical exploitation: Lazarus, UNC6201, Silk Typhoon, and CISA's past action

Dell's advisory notes that it has not flagged these new CSM flaws as being actively exploited. Still, the company and outside researchers have documented state-sponsored abuse of other Dell vulnerabilities in recent years.

  • North Korea's Lazarus group exploited an insufficient access control vulnerability in the Dell dbutil driver (CVE-2021-21551) to deploy a Windows rootkit on victims' systems.
  • In February, Mandiant and the Google Threat Intelligence Group (GTIG) revealed that a suspected Chinese state-backed group, UNC6201, had been exploiting a maximum-severity hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to deploy malware payloads and create hidden network interfaces on VMware ESXi servers.
  • Those researchers also reported overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, which had previously targeted government agencies with custom Spawnant and Zipline malware in Ivanti zero-day attacks.
  • Following those findings, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch vulnerable Dell systems on their networks within three days.

What this means for technologists, government agencies, and adversaries

  • Technologists and security teams: Dell's advisory and the availability of fixes make upgrading to CSM version 1.18.0 or later the immediate operational task. The breadth of the flaws — ranging from credential exposure to the ability to read Kubernetes Secrets cluster-wide — means patch prioritization should focus on clusters that register Dell arrays and use CSM.
  • Government agencies: Because CISA previously ordered rapid patching of vulnerable Dell systems after other high-severity findings, agencies will likely evaluate CSM exposure quickly and consider accelerated patch timelines for CSM installations tied to critical infrastructure or multi-tenant environments.
  • Adversaries and threat actors: Dell notes it has not observed active exploitation of these specific CSM flaws. Historical precedents cited in the advisory — Lazarus, UNC6201, and overlaps with Silk Typhoon — demonstrate that state-backed groups have targeted Dell products in the past, elevating the potential attractiveness of maximum-severity CSM flaws to sophisticated attackers.

Dell has issued an immediate software remedy and a clear upgrade path. The company warns that unauthenticated attackers could gain sweeping administrative control if these authorization weaknesses are exploited; at the same time, Dell has not reported in-the-wild exploitation of these specific CSM defects. The practical choice facing operators is simple and binary: apply version 1.18.0 or later as soon as possible, then watch whether regulators or agencies issue expedited patching directives similar to prior CISA action.

Source: https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/