VMTech
Discuss a project →

Dell updates CSM after critical Kubernetes storage vulnerabilities

Dell updates CSM after critical Kubernetes storage vulnerabilities

Dell has released Container Storage Modules (CSM) version 1.18.0 to address six critical vulnerabilities affecting every CSM release before 1.17.0. The flaws include two CVSS 10.0 issues that could give unauthenticated attackers access to storage administrator credentials or administrative privileges, as well as a CVSS 9.9 vulnerability that could lead to root-level access on Kubernetes nodes.

The affected components include the csm-authorization-storage gRPC server, the authorization proxy and tenant service, the CSM Authorization module, karavi-authorization, and the ContainerStorageModule Custom Resource reconciler. Dell said there are no workarounds or mitigations other than installing the updated release.

Authentication bypass and forged administrative tokens

CVE-2026-63688 is a missing-authentication vulnerability in the csm-authorization-storage gRPC server. Dell assigned it a CVSS score of 10.0 and said an unauthenticated remote attacker could obtain storage backend administrator credentials for all registered storage arrays. The company described the issue as a complete bypass of the csm-authorization security model affecting storage infrastructure across all five supported Dell storage product families.

CVE-2026-63692, also rated 10.0, affects the authorization proxy and tenant service. An unauthenticated network attacker could bypass authentication controls, gain administrative-level privileges, and access or manipulate storage resources across tenants.

Two further issues expose the authorization layer to token forgery. CVE-2026-54472, with a CVSS score of 9.8, stems from hard-coded credentials in the CSM Authorization module and could allow an unauthenticated remote attacker to forge cryptographically valid administrative tokens. CVE-2026-61421, also rated 9.8, involves a hard-coded cryptographic key in the JWT authentication component of karavi-authorization; an attacker who knows the publicly available signing secret could forge tokens and obtain administrative privileges.

Paths to Kubernetes node compromise

CVE-2026-67269 is an improper privilege-management issue in the ContainerStorageModule Custom Resource reconciler. Rated 9.9, it could permit a low-privilege remote attacker to escalate privileges and gain root-level access on cluster nodes. Dell said a single custom resource submission could be used to compromise all nodes in a Kubernetes cluster.

The node-level risk aligns with container escape paths to host root where a container escape can reach host root, because both scenarios require defenders to treat Kubernetes control paths and node privileges as a single security boundary.

CVE-2026-67273, rated 9.6, is an improper neutralization of special elements in a template engine. Dell said a low-privilege attacker with remote access could use it to escalate privileges, access sensitive information, and tamper with RBAC. Successful exploitation can provide cluster-wide read access to Kubernetes Secrets and permit creation of cluster-scoped RBAC resources, bypassing intended Kubernetes access controls.

Actions for CSM operators

Dell recommends upgrading affected environments to CSM 1.18.0 and rotating JWT signing secrets. Teams should identify CSM instances below 1.17.0, prioritize clusters with exposed authorization services or shared tenant storage, and review administrative tokens, Kubernetes Secrets access, custom resource permissions, and cluster-scoped RBAC after the update. The practical implication is that upgrading and key rotation should be handled as one operational change, followed by validation that storage and Kubernetes authorization paths still enforce least privilege.

#kubernetes#cloudsecurity#dellcsm#vulnerability
Open analytics
On the site 0 views
min read 4 02.10.2026
Instagram

Dell updates CSM after critical Kubernetes storage vulnerabilities

Open the post on Instagram ↗