Dell Urgent Patch: Critical CSM Vulnerabilities Require Immediate Action
Dell has resolved two critical vulnerabilities in its Container Storage Modules (CSM), impacting enterprise storage systems integrated with Kubernetes environments.
Overview of Vulnerabilities
Dell identified two maximum-severity flaws in the CSM Authorization security module, stemming from insufficient authentication mechanisms. These vulnerabilities affect critical functions and support Dell’s primary storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT.
CVE-2026-63688: Unauthorized Access to Administrator Credentials
This vulnerability allows unauthenticated remote attackers to access storage backend administrator credentials, posing a significant risk to data security.
CVE-2026-63692: Bypassing Authentication Controls
Threat actors can exploit this flaw to bypass authentication controls and gain administrative privileges through the authorization proxy and tenant service, enabling unauthorized manipulation of storage resources.
Dell emphasized that these issues pose significant risks, as they could grant unauthorized access to and manipulation of storage resources across all tenants.
Additional Critical Vulnerabilities
Dell also resolved four other critical-severity vulnerabilities in the CSM. These include:
- CVE-2026-67269: Remote attackers can achieve root access on cluster nodes without prior privileges.
- CVE-2026-54472: Administrative access to the CSM Authorization proxy is possible.
- CVE-2026-61421: Forged authentication tokens enable administrative privileges.
- CVE-2026-67273: Bypasses Kubernetes access controls to grant cluster-wide read access to Secrets.
Recommendations and Mitigation
Dell advises customers to update their CSM installations to version 1.18.0 or later to mitigate these risks. The company has not confirmed active exploitation but highlights the urgency, citing historical precedents such as the Lazarus group exploiting similar flaws in Dell systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) previously mandated government agencies to patch vulnerable Dell systems within three days.
Enterprises using Dell storage solutions are urged to prioritize the latest updates to prevent potential breaches.
