Dell storage modules can hand over array admin with no login

By George Bailey   Published: 10/05/26   4 min read

If Dell Container Storage Modules sit between your Kubernetes cluster and the storage arrays, an unauthenticated caller can ask for the array admin passwords. Dell shipped the fixes in CSM 1.18.0 on October 2. There is no workaround. This is not “wait for the next platform sprint.”

No login, and the storage admin passwords come back.

What happened

Dell’s Container Storage Modules connect Power-family and other Dell arrays to Kubernetes. The Hacker News write-up of the October 2 updates lists six critical issues, two of them scored 10.0 because authentication is simply missing.

CVE-2026-63688 is missing authentication on the csm-authorization-storage gRPC server. An unauthenticated remote attacker can retrieve storage-backend administrator credentials for every registered array. Dell’s own description, quoted in coverage of the advisory, is a complete bypass of the csm-authorization model across the supported Dell storage families.

CVE-2026-63692 is missing authentication on the authorization proxy and tenant service. Same shape: no login, administrative control of the authorization service, and the ability to touch storage across tenants.

The rest of the set is how that foothold gets worse. CVE-2026-67269 (9.9) lets a low-privilege caller submit one ContainerStorageModule custom resource and reach root on cluster nodes — Dell says that can cover every node. CVE-2026-54472 and CVE-2026-61421 (both 9.8) are hard-coded credentials and a hard-coded JWT signing secret in karavi-authorization, so an attacker who knows the public secret can forge an admin token. CVE-2026-67273 (9.6) is template injection that can read Kubernetes Secrets cluster-wide and create cluster-scoped RBAC.

Dell says the flaws affect CSM before 1.17.0 and are addressed in 1.18.0, with no workaround other than the update. There is no public report of exploitation in the wild for this set as of this brief. The blast radius is why it is on Monday’s list anyway: storage admin credentials plus node root is the cluster, not a dashboard bug.

Why it matters

Whoever can read the array admin password can read the volumes. Whoever can root a node from a custom resource can read every pod that lands there. Teams that treat CSI drivers as “platform, not security” will not see this in the app-sec queue.

Rotate secrets after you patch. A hard-coded JWT key means any token minted before the upgrade stays interesting until the signing secret changes.

What to do first

Forward this

If you own the Kubernetes platform or the storage arrays behind it: upgrade Dell Container Storage Modules to 1.18.0 and rotate the JWT signing secret plus the array admin passwords. There is no config-only workaround.

Details

Hunt / verify

Slack paste: Dell CSM before 1.18.0: unauthenticated storage-admin credential leak plus a path to node root. Upgrade to 1.18.0, rotate JWT secrets and array admin passwords. CVE-2026-63688 and CVE-2026-63692 are the CVSS 10 pair.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.