Dell has patched six critical vulnerabilities in its Container Storage Modules (CSM), which connect Dell enterprise storage arrays to Kubernetes environments. The company recommends that customers upgrade to version 1.18.0 or later at the earliest opportunity.
Two flaws affect the CSM Authorization security module. Dell said both stem from missing authentication for critical functions. CVE-2026-63688 could let unauthenticated remote attackers obtain administrator credentials for registered storage arrays and bypass authorization to take control of storage infrastructure. CVE-2026-63692, in the authorization proxy and tenant service, could let attackers bypass authentication and gain administrative privileges.
Dell also patched four other critical issues. They could allow remote attackers to gain root access on cluster nodes (CVE-2026-67269), obtain administrative access to the CSM Authorization proxy (CVE-2026-54472), forge authentication tokens for administrative privileges (CVE-2026-61421), or bypass Kubernetes access controls to read Kubernetes Secrets across a cluster (CVE-2026-67273).
CSM supports Dell storage platforms including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT, and extends Kubernetes Container Storage Interface drivers. Dell has not flagged these vulnerabilities as actively exploited. The company said customers should update their container storage modules to address the flaws.
Comments
0No comments yet. Be the first to comment.