thehackernews.com 2 Oct 2026, 17:02 UTC

Dell Fixes Critical CSM Flaws Letting Attackers Seize Kubernetes Clusters

DELL has released security updates for Dell Container Storage Modules (CSM) to fix a set of critical flaws that could let unauthenticated attackers seize control of storage infrastructure and Kubernetes clusters. The vendor’s advisory lists six CVEs with high CVSS scores, including CVE-2026-63688 (score 10.0) for missing authentication in the csm-authorization-storage gRPC server, which could grant unauthorized access to storage backend administrator credentials across all registered storage arrays.

Additional critical issues include CVE-2026-63692 (score 10.0) in the authorization proxy and tenant service allowing authentication bypass, CVE-2026-67269 (score 9.9) in the ContainerStorageModule Custom Resource reconciler enabling root-level cluster access, CVE-2026-54472 (score 9.8) involving hard-coded credentials to forge admin tokens, CVE-2026-61421 (score 9.8) in the

JWT component enabling token forging, and CVE-2026-67273 (score 9.6) related to template engine input handling that could escalate privileges and tamper RBAC.

Dell explains that these flaws collectively permit a complete bypass of the csm-authorization security model and, in effect, give an attacker cluster-wide control over the storage stack covering Dell’s five supported storage families. The issues affect all CSM versions prior to 1.17.0 and are addressed in 1.18.0; there are no mitigations other than updating. Dell’s guidance to customers is clear: apply the updates and rotate JWT signing secrets to reduce exposure.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline