Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Broken Clouds Humidity: 90%
Wind: 0 M/S

Unauthenticated Attackers Can Achieve Administrative and Root Access Through Dell CSM Vulnerabilities

Unauthenticated Attackers Can Achieve Administrative and Root Access Through Dell CSM Vulnerabilities

Dell has released a series of security updates to address several critical vulnerabilities affecting Dell Container Storage Modules (CSM), warning that the flaws could allow attackers to bypass authentication, obtain administrative privileges, steal sensitive credentials, and even gain root-level control of Kubernetes nodes. If exploited, the vulnerabilities could provide a pathway for threat actors to take over storage infrastructure and compromise entire Kubernetes environments.

The newly disclosed issues impact various components of the CSM ecosystem and carry CVSS scores ranging from 9.6 to 10.0, placing them among the most severe security risks organizations can face.

Critical Vulnerabilities Addressed

Among the most serious flaws is CVE-2026-63688 (CVSS 10.0), which stems from missing authentication controls within the csm-authorization-storage gRPC server. The vulnerability allows an unauthenticated remote attacker to access storage backend administrator credentials associated with all registered storage arrays. With those credentials, an attacker could gain extensive control over storage resources across affected environments.

Another maximum-severity issue, CVE-2026-63692 (CVSS 10.0), affects the authorization proxy and tenant service. The flaw enables unauthenticated attackers to bypass authentication mechanisms entirely and obtain administrative privileges without requiring valid credentials.

Dell also patched CVE-2026-67269 (CVSS 9.9), an improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler. An attacker with limited privileges could abuse the weakness to elevate permissions and ultimately gain root-level access on Kubernetes cluster nodes.

In addition, CVE-2026-54472 (CVSS 9.8) was found in the CSM Authorization module. The issue involves hard-coded credentials that could allow unauthenticated attackers to forge legitimate administrative tokens and gain unauthorized access to the CSM Authorization proxy.

The company further addressed CVE-2026-61421 (CVSS 9.8), a hard-coded cryptographic key vulnerability affecting the JWT authentication mechanism used by karavi-authorization. Because the signing secret is publicly known, attackers could create forged authentication tokens and elevate their privileges to administrator level.

Rounding out the list is CVE-2026-67273 (CVSS 9.6), a template injection vulnerability that could enable a low-privileged remote attacker to escalate privileges, access confidential information, and manipulate Kubernetes Role-Based Access Control (RBAC) configurations.

Potential Impact on Storage and Kubernetes Environments

Dell highlighted the especially severe nature of CVE-2026-63688, noting that the vulnerability effectively undermines the entire CSM authorization framework. Successful exploitation could allow attackers to bypass the security model completely and assume administrative control over storage infrastructure spanning all five supported Dell storage product families.

Similarly, the vendor warned that CVE-2026-63692 could grant an unauthenticated attacker full control of the authorization service, enabling them to view, modify, or misuse storage resources across multiple tenants.

The risks extend beyond storage management. According to Dell, CVE-2026-67269 could be leveraged to compromise every node within a Kubernetes cluster through a single malicious custom resource submission. Such an attack could result in cluster-wide compromise, allowing threat actors to establish persistence and potentially gain unrestricted access to workloads and data.

The hard-coded credential issue tracked as CVE-2026-54472 poses an additional threat by enabling attackers to forge valid administrative tokens. This capability could be used to bypass authentication safeguards within the authorization proxy and unlawfully manage storage access policies across connected tenant environments.

Kubernetes Secrets and RBAC at Risk

Dell's advisory for CVE-2026-67273 states that successful exploitation could provide attackers with read access to Kubernetes Secrets across the entire cluster. In addition, malicious actors could create cluster-scoped RBAC resources, effectively circumventing Kubernetes' intended access control mechanisms and expanding their privileges throughout the environment.

Because Kubernetes Secrets often contain API keys, credentials, certificates, and other sensitive information, compromise of these resources can quickly lead to broader infrastructure breaches.

Patch Availability and Recommended Actions

The vulnerabilities affect all Dell Container Storage Module releases prior to version 1.17.0. Dell has fully addressed the issues in CSM version 1.18.0 and strongly recommends that customers upgrade as soon as possible.

Importantly, Dell noted that there are no available workarounds or temporary mitigations for the vulnerabilities. Updating to the fixed version remains the only effective method of eliminating the risk.

In addition to applying the patches, the company advises organizations to rotate all JWT signing secrets to prevent the misuse of previously exposed authentication keys and tokens.

Given the history of active exploitation involving past Dell vulnerabilities such as CVE-2021-21551 and CVE-2026-22769, security teams should treat these newly disclosed flaws as high-priority remediation items. Prompt patching and credential rotation can help prevent attackers from exploiting these weaknesses to gain administrative access, compromise Kubernetes clusters, and take control of critical storage infrastructure.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.