Dell patches max severity CSM flaws enabling admin takeover
Dell has fixed two maximum severity vulnerabilities in Container Storage Modules (CSM), the software that links the company's enterprise storage arrays to Kubernetes environments. The company is urging customers to update as soon as possible.
CSM works with Dell's main storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT. It adds features on top of the standard Container Storage Interface (CSI) drivers, which Kubernetes uses to talk to external storage systems.
Two critical flaws in the Authorization module
According to a security advisory Dell published on Thursday, both flaws sit in the CSM Authorization security module. Dell traces both to the same type of weakness: "missing authentication for critical functions."
The first, CVE-2026-63688, lets a remote attacker with no credentials obtain the storage backend administrator credentials for every registered storage array. The attacker can then bypass authorization and take full administrative control of the storage infrastructure.
The second, CVE-2026-63692, affects the authorization proxy and tenant service. An attacker who exploits it can bypass authentication controls and gain admin privileges.
"This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants," Dell said.
Four more critical bugs fixed the same day
Dell also patched four other critical-severity CSM issues on the same day. Remote attackers without privileges can exploit all of them. The flaws allow an attacker to:
- gain root on cluster nodes (CVE-2026-67269)
- gain administrative access to the CSM Authorization proxy (CVE-2026-54472)
- forge authentication tokens to obtain administrative privileges (CVE-2026-61421)
- bypass Kubernetes access controls to read Kubernetes Secrets across the whole cluster (CVE-2026-67273)
"Dell recommends customers to upgrade at the earliest opportunity," the company said. The fixes are in CSM version 1.18.0 and later.
Dell bugs have drawn state-backed attackers before
Dell has not said that any of these vulnerabilities are being exploited. Still, state-sponsored groups have targeted other Dell flaws in recent years.
North Korea's Lazarus group exploited an insufficient access control flaw (CVE-2021-21551) in the Dell dbutil driver to install a Windows rootkit on victims' machines.
In February, Mandiant and the Google Threat Intelligence Group (GTIG) reported that UNC6201, a suspected Chinese state-backed group, had been exploiting CVE-2026-22769 since at least mid-2024. That maximum severity hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines let the attackers deploy malware and create hidden network interfaces on VMware ESXi servers.
The researchers found overlaps between UNC6201 and Silk Typhoon, a Chinese cyberespionage group known for targeting government agencies with its custom Spawnant and Zipline malware in Ivanti zero-day attacks. A few days after that disclosure, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the federal agency responsible for civilian government network security, ordered agencies to patch affected Dell systems within three days.
Why it matters
The CSM flaws are serious because of where the module sits. CSM Authorization controls access to storage shared by many tenants, so one unauthenticated bug can expose data across the whole environment. The Secrets exposure in CVE-2026-67273 adds to the risk. Kubernetes Secrets often hold the kind of tokens and passwords that let attackers move to other systems, a problem we also covered with still-valid credentials leaking from GitHub repos.
There are no reports of exploitation yet. But the RecoverPoint case shows that state-backed groups will go after Dell infrastructure products, and in that case the attacks went unnoticed for a long time. Infrastructure management software is a frequent target. Recent attacks on Cisco SD-WAN Manager and NetScaler appliances tied to state hackers follow the same pattern.
Teams running CSM should move to version 1.18.0 and consider rotating storage backend credentials and any Secrets that may have been exposed. It is also worth watching whether CISA adds any of these CVEs to its list of actively exploited vulnerabilities in the coming weeks.
