DELL has fixed two CVSS 10 flaws in its Container Storage Modules (CSM) that would allow unauthenticated attackers to gain full administrative control of the storage layer. The company urges users to upgrade to version 1.18.0 or later. The advisory also confirms a broader set of 24 CVEs across third‑party Go libraries, and 13 Dell‑specific CVEs, with overall impact rated Critical. At the time of reporting, Dell notes no known exploitation in the wild and no public PoCs.
The most severe flaws are CVE-2026-63688 and CVE-2026-63692, described as authentication gaps in the csm-authorization-storage gRPC server and the authorization proxy/tenant service respectively. Dell warns a remote attacker could obtain administrator credentials for all registered storage arrays and bypass login checks to reach storage resources across all tenants.
Additional high‑impact issues include CVE-2026-67269 and CVE-2026-67273, affecting the CSM Operator’s reconciler and a template engine flaw that could grant cluster‑wide read access to Kubernetes Secrets, potentially enabling a cluster takeover or data exposure. Other notable problems include hard‑coded credentials in CVE-2026-54472 and an exposed sample JWT secret in CVE-2026-61421 tied to the archived karavi-authorization project.
Affected versions are listed as prior to 1.17.0, though Dell notes the table may not be comprehensive across CSM Authorization 2.4.0, CSM Operator 1.12.0, and even 1.18.0. Patching guidance is explicit: upgrade to 1.18.0 or newer, rotate all JWT signing secrets, replace storage backend admin passwords, retire karavi-authorization, and restrict network access to CSM authorization services while auditing RBAC.