Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7
Tag: hardcoded-credentials (1 article)Clear

Critical Dell storage module flaws grant unauthenticated admin access and root on Kubernetes nodes

Dell released updates for multiple critical flaws in Dell Container Storage Modules that could let attackers take over affected systems. CVE-2026-63688, rated 10.0, is missing authentication in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could use to obtain storage backend administrator credentials for all registered arrays. CVE-2026-63692, also 10.0, lets an unauthenticated network attacker bypass authentication in the authorization proxy and tenant service to gain administrative privileges. CVE-2026-67269, rated 9.9, lets a low-privilege attacker escalate to root on cluster nodes, and CVE-2026-54472, rated 9.8, uses hard-coded credentials to forge valid administrative tokens. Together they expose storage credentials, cluster nodes, and the authorization layer in Kubernetes environments.

Check
Inventory Kubernetes clusters using Dell Container Storage Modules, apply Dell's fixed module versions promptly, and rotate storage backend credentials that may be exposed.
Affected
Kubernetes clusters running vulnerable Dell CSM versions expose storage admin credentials, allow authentication bypass, and permit escalation to root on cluster nodes.
Fix
Update Dell CSM modules, rotate storage array and token-signing credentials, restrict access to the CSM authorization services, and review cluster node integrity.