If Dell Container Storage Modules sit between your Kubernetes cluster and the storage arrays, an unauthenticated caller can ask for the array admin passwords. Dell shipped the fixes in CSM 1.18.0 on October 2. There is no workaround. This is not “wait for the next platform sprint.”
No login, and the storage admin passwords come back.
What happened
Dell’s Container Storage Modules connect Power-family and other Dell arrays to Kubernetes. The Hacker News write-up of the October 2 updates lists six critical issues, two of them scored 10.0 because authentication is simply missing.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
CVE-2026-63688 is missing authentication on the csm-authorization-storage gRPC server. An unauthenticated remote attacker can retrieve storage-backend administrator credentials for every registered array. Dell’s own description, quoted in coverage of the advisory, is a complete bypass of the csm-authorization model across the supported Dell storage families.
CVE-2026-63692 is missing authentication on the authorization proxy and tenant service. Same shape: no login, administrative control of the authorization service, and the ability to touch storage across tenants.
The rest of the set is how that foothold gets worse. CVE-2026-67269 (9.9) lets a low-privilege caller submit one ContainerStorageModule custom resource and reach root on cluster nodes — Dell says that can cover every node. CVE-2026-54472 and CVE-2026-61421 (both 9.8) are hard-coded credentials and a hard-coded JWT signing secret in karavi-authorization, so an attacker who knows the public secret can forge an admin token. CVE-2026-67273 (9.6) is template injection that can read Kubernetes Secrets cluster-wide and create cluster-scoped RBAC.
Dell says the flaws affect CSM before 1.17.0 and are addressed in 1.18.0, with no workaround other than the update. There is no public report of exploitation in the wild for this set as of this brief. The blast radius is why it is on Monday’s list anyway: storage admin credentials plus node root is the cluster, not a dashboard bug.
Why it matters
Whoever can read the array admin password can read the volumes. Whoever can root a node from a custom resource can read every pod that lands there. Teams that treat CSI drivers as “platform, not security” will not see this in the app-sec queue.
Rotate secrets after you patch. A hard-coded JWT key means any token minted before the upgrade stays interesting until the signing secret changes.
What to do first
- Find every cluster running Dell CSM, including labs that were promoted.
kubectl get pods -A | grep -i csmis a start, not the inventory. - Upgrade CSM to 1.18.0 or later. Dell’s stated fix line is 1.18.0. Do not stop on 1.17.0.
- Rotate JWT signing secrets used by CSM Authorization, and rotate storage-array administrator credentials that the module could see.
- Review Kubernetes audit logs for unexpected ContainerStorageModule custom resources, new ClusterRoleBindings, and reads of Secrets from the CSM service accounts.
- If the authorization gRPC port was reachable beyond the cluster network, treat credential theft as plausible and rotate even if you see no logs.
Forward this
If you own the Kubernetes platform or the storage arrays behind it: upgrade Dell Container Storage Modules to 1.18.0 and rotate the JWT signing secret plus the array admin passwords. There is no config-only workaround.
Details
- Fixed release: Dell CSM 1.18.0 (October 2, 2026). Affected: versions before 1.17.0, per Dell as reported by The Hacker News. No workaround.
- CVE-2026-63688 — missing auth on csm-authorization-storage gRPC; unauthenticated retrieval of storage admin credentials. CVSS 10.0.
- CVE-2026-63692 — missing auth on the authorization proxy and tenant service; unauthenticated admin. CVSS 10.0.
- CVE-2026-67269 — ContainerStorageModule reconciler privilege bug; low-priv to root on nodes. CVSS 9.9.
- CVE-2026-54472 — hard-coded credentials; forge admin tokens. CVSS 9.8.
- CVE-2026-61421 — hard-coded JWT signing key in karavi-authorization. CVSS 9.8.
- CVE-2026-67273 — template injection; cluster Secret read and RBAC tampering. CVSS 9.6.
- Exploitation: not reported in the wild for this set as of October 4, 2026.
Hunt / verify
- Confirm the running CSM image tag is 1.18.0 or newer on every cluster, not just production.
- Confirm JWT signing secrets and array admin passwords were rotated after the upgrade, not before.
- Audit for ContainerStorageModule objects you did not create.
Slack paste: Dell CSM before 1.18.0: unauthenticated storage-admin credential leak plus a path to node root. Upgrade to 1.18.0, rotate JWT secrets and array admin passwords. CVE-2026-63688 and CVE-2026-63692 are the CVSS 10 pair.
Sources
- https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.