Skip to main content

Dell Container Storage Modules Flaws Expose Storage Admin Credentials Without Any Login (CVE-2026-63688 / CVE-2026-63692)

Scope: Dell Container Storage Modules (CSM) prior to version 1.17.0, including CSM Authorization 2.4.0, used with PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT arrays

Severity: Red

Dell published advisory DSA-2026-448 on October 1, 2026, fixing two maximum severity flaws in Container Storage Modules, the software that connects Dell storage arrays to Kubernetes clusters. CVE-2026-63688 (CVSS 10.0) is a missing authentication flaw in the csm-authorization-storage gRPC server that lets an unauthenticated remote attacker obtain the backend administrator credentials for every storage array registered with CSM. CVE-2026-63692 (CVSS 10.0) is a second missing authentication flaw, in the authorization proxy and tenant service, that lets an attacker bypass authentication and gain administrative privileges, exposing storage resources across all tenants. The same advisory fixes CVE-2026-67269 (CVSS 9.9), which can give root on cluster nodes through the CSM Operator, and CVE-2026-54472 (CVSS 9.8), where hard-coded credentials allow an attacker to forge valid admin tokens. Dell lists no workarounds and no known exploitation so far. Organisations using CSM must upgrade to version 1.18.0 or later, rotate all JWT signing secrets, replace the storage backend admin passwords that CSM holds, and limit network access to the CSM Authorization services while the upgrade is rolled out.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.