Critical Dell CSM Flaws Grant Unauthenticated Admin Access and Root on Kubernetes
Multiple critical vulnerabilities in Dell Container Storage Modules (CSM) allow unauthenticated attackers to gain administrative control over storage arrays and root privileges on Kubernetes nodes.

Dell has issued urgent security updates to address a series of critical vulnerabilities within its Container Storage Modules (CSM) software. These flaws, some carrying a CVSS score of 10.0, could allow unauthenticated remote attackers to achieve complete administrative control over storage infrastructure and gain root-level access on Kubernetes nodes.
The most severe vulnerability, CVE-2026-63688, resides in the csm-authorization-storage gRPC server. It's a missing authentication for critical function flaw that enables an unauthenticated remote attacker to steal administrator credentials for all registered storage arrays. Dell emphasized that this vulnerability represents a complete bypass of the CSM security model, granting full administrative control across all five supported Dell storage product families.
Another critical flaw, CVE-2026-63692, also rated CVSS 10.0, affects the authorization proxy and tenant service. This missing authentication vulnerability allows an unauthenticated network attacker to bypass security controls and obtain administrative privileges over the authorization service, potentially impacting storage resources across all tenants.
Further compounding the risk, CVE-2026-67269, an improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler, allows a low-privilege remote attacker to escalate their privileges and gain root access on cluster nodes. Dell noted that a single custom resource submission could be used to compromise an entire Kubernetes cluster.
Additional vulnerabilities include CVE-2026-54472 (CVSS 9.8), a use of hard-coded credentials in the CSM Authorization module, which could be exploited to forge administrative tokens. CVE-2026-61421 (CVSS 9.8) involves a hard-coded cryptographic key in the JWT authentication component, allowing attackers to forge authentication tokens. Lastly, CVE-2026-67273 (CVSS 9.6) is an improper neutralization of special elements vulnerability that could lead to privilege escalation and unauthorized RBAC tampering.
These vulnerabilities affect all versions of Dell CSM prior to version 1.17.0. Dell has released version 1.18.0 to address these issues. The company strongly advises customers to update to the latest version immediately, as there are no effective workarounds or mitigations available other than applying the patch.
Given the critical nature of these flaws and the potential for widespread compromise, prompt patching is essential. The exploitation of vulnerabilities in Dell products has been observed in recent years, highlighting the importance of maintaining up-to-date security measures for Dell hardware and software.
Organizations utilizing Dell Container Storage Modules should prioritize this update to safeguard their storage infrastructure and Kubernetes environments from potential exploitation.