---
title: "Dell Patches Two CVSS 10 Container Storage Modules Flaws"
date: 2026-10-02
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/10/dell-cybersecurity-infrastructure-alert.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Dell Patches Two CVSS 10 Container Storage Modules Flaws

Dell Technologies on October 1, 2026 patched two maximum-severity Container Storage Modules flaws that expose administrator credentials for every registered storage array. Both bugs carry a CVSS score of 10.0, and neither requires a login.

## The Brief

- CVE-2026-63688 lets a remote attacker with no credentials pull storage admin credentials for every array registered with CSM.
- CVE-2026-63692 bypasses authentication in the authorization proxy and tenant service, exposing storage resources across all tenants.
- Four more critical CSM bugs, scored 9.6 to 9.9, open paths to root on cluster nodes and to forged admin tokens.
- Dell has reported no exploitation in the wild, and no public proof-of-concept code has surfaced yet.

## Two authentication gaps expose every connected array

CSM links Kubernetes clusters to Dell’s primary storage platforms: **PowerStore**, **PowerScale**, **PowerFlex**, **PowerMax** and **Unity XT**. Many teams run it in production to give containers persistent storage. Its authorization service often holds admin keys for every array it fronts, so one flaw here reaches well past a single app or namespace.

**CVE-2026-63688** lives in the csm-authorization-storage gRPC server. Dell said in its [DSA-2026-448 advisory](https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities) that an unauthenticated attacker could grab backend administrator credentials for all registered arrays. That access gives “**full administrative control over the storage infrastructure**” across all five supported product families.

CVE-2026-63692 sits in the authorization proxy and tenant service, where it skips login checks entirely. Dell rates it critical because an attacker could take over the authorization service and then read or alter storage resources belonging to every tenant.

> Dell asks admins to patch max severity CSM flaws as soon as possible www.​bleepingcomputer.​com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/ [\#Security](https://x.com/hashtag/Security?src=hash&ref_src=twsrc%5Etfw) [pic.twitter.com/RyQHUIEUX6](https://t.co/RyQHUIEUX6)
> 
> — The Cyber Security Hub™ (@TheCyberSecHub) [October 2, 2026](https://x.com/TheCyberSecHub/status/2106000968261468257?ref_src=twsrc%5Etfw)

 ## Operator and token flaws push the damage into Kubernetes

The cluster itself is the next target. **CVE-2026-67269**, rated **9.9**, abuses the CSM Operator’s custom resource reconciler. Dell warned that one custom resource submission from a low-privileged user could compromise every node with root access. **CVE-2026-67273**, rated **9.6**, uses a template engine flaw to grant cluster-wide read access to Kubernetes Secrets.

Two more bugs, each rated **9.8**, come down to baked-in secrets. CVE-2026-54472 ships hard-coded credentials that let attackers forge valid admin tokens. CVE-2026-61421 affects the archived karavi-authorization project, whose old setup guide printed a sample JWT signing secret. Any team that copied it and never rotated the key may still be exposed.

That bug class has a history at Dell. In February, Mandiant and the Google Threat Intelligence Group tied suspected Chinese state-backed group **[UNC6201 to CVE-2026-22769](https://sqmagazine.co.uk/dell-recoverpoint-zero-day-chinese-hackers/)**. That maximum-severity hard-coded credential flaw in Dell RecoverPoint for Virtual Machines had been exploited since at least mid-2024. CISA then ordered federal agencies to patch it within three days.

The advisory lists 13 [Dell-specific CVEs](https://sqmagazine.co.uk/kev-tracker/), plus fixes for third-party Go libraries such as **golang.org/x/crypto, golang.org/x/net, golang-jwt and protobuf**. Dell names CSM releases before 1.17.0 as affected, yet several CVE entries cite CSM Authorization 2.4.0, CSM Operator 1.12.0 and even 1.18.0. Dell also concedes its version table may be incomplete. That leaves an open question for anyone who already upgraded: does 1.18.0 close every CVE that names it?

## What’s Next?

For teams already running CSM, these steps help reduce risk:

- **Upgrade to CSM 1.18.0 or later, since Dell offers no workaround.**
- **Rotate every JWT signing secret, as Dell advises for CVE-2026-54472.**
- **Replace the storage backend admin passwords CSM holds, because CVE-2026-63688 targets exactly those.**
- **Retire any karavi-authorization deployment, which is no longer maintained.**
- **Restrict network access to CSM authorization services and check RBAC roles for changes nobody approved.**

The practical marker is the upgrade itself, because every CSM release below 1.18.0 sits on Dell’s affected list today. An upgrade does nothing about keys an attacker may already have copied. That is why secret rotation belongs in the same change window, and the RecoverPoint case shows how long a credential flaw can go unnoticed.