Dell shipped advisory DSA-2026-448 on October 1 for Container Storage Modules (CSM), the software that connects Dell PowerFlex, PowerMax, PowerScale, PowerStore and Unity arrays to Kubernetes through CSI drivers. The update fixes six critical flaws, two of them rated CVSS 10.0. Both are missing-authentication bugs in the CSM Authorization module, reachable over the network without credentials. Dell says there are no workarounds. At the time of writing no in-the-wild exploitation has been reported.

What was fixed

CVE-2026-63688 (CVSS 10.0) is a missing authentication for a critical function in the csm-authorization-storage gRPC server. An unauthenticated remote attacker can call the service and retrieve the storage backend administrator credentials for every storage array registered with the authorization proxy.

CVE-2026-63692 (CVSS 10.0) is a missing authentication flaw in the authorization proxy and tenant service. An unauthenticated network attacker can bypass authentication and act with administrative privileges over the proxy, including tenant and role management.

CVE-2026-54472 (CVSS 9.8) is a hard-coded credential in the CSM Authorization module. An attacker who knows the embedded secret can forge cryptographically valid administrative tokens and gain admin access to the proxy.

CVE-2026-61421 (CVSS 9.8) is a hard-coded cryptographic key in the archived karavi-authorization component, again permitting forged authentication tokens.

The advisory also covers CSM Operator and CSI components, including CVE-2026-67269, which reporting describes as a path to root on Kubernetes cluster nodes, plus third-party Go library updates. Public write-ups point out that pairing CVE-2026-63688 with the node-level flaw means one unauthenticated request could compromise both the storage tier and the compute tier. Dell’s full advisory text was not retrievable at publication time, so confirm per-CVE details against DSA-2026-448.

Affected versions

All Container Storage Modules releases before 1.17.0 are affected. The fixes ship in CSM 1.18.0 and later. The standalone CSM Authorization proxy is the primary exposure; clusters that only run the CSI drivers without the authorization module have a smaller attack surface for the CVSS 10 pair but should still update.

Impact

The authorization proxy exists to keep storage array admin credentials out of the hands of individual Kubernetes clusters and tenants. That makes it a concentrated secret store: compromising it hands an attacker the array admin account for every backend it fronts. From there an attacker can:

  • Read, snapshot, clone or delete persistent volumes, including those holding databases, etcd backups and application secrets.
  • Provision or remap volumes to attacker-controlled hosts.
  • Destroy data and backups on the array, which is attractive for ransomware and extortion operators.
  • Forge tokens (CVE-2026-54472 and CVE-2026-61421) to persist even if a single credential is rotated, until the keys are replaced by upgrading.

Because the flaws need no authentication, any host that can reach the proxy’s listener is a potential attacker. In flat cluster networks that includes every pod.

Mitigation

  1. Upgrade to CSM 1.18.0 or later. Dell states no workaround exists.
  2. Restrict network access now. Until patched, limit the CSM Authorization ingress and gRPC ports to the specific cluster nodes and management hosts that need them. Use Kubernetes NetworkPolicy and perimeter firewall rules.
  3. Rotate credentials after patching. Treat storage backend admin credentials registered in the proxy as exposed on any instance that was reachable from untrusted networks. Rotate them on the arrays and re-register. Replace any tenant tokens and signing material generated under affected versions.
  4. Hunt for abuse. Review proxy and array audit logs for unfamiliar tenants or roles, unexpected volume mappings, new array admin sessions, and gRPC calls from addresses outside your cluster.
  5. Inventory. Find CSM deployments with helm list -A and kubectl get csm -A, and check image tags against 1.17.0.

Why it matters

These bugs follow a familiar pattern: a security component added to isolate secrets ships with unauthenticated endpoints or baked-in keys, and ends up as the single most valuable target in the environment. Storage control planes get less scrutiny than ingress controllers or API servers, yet they hold the keys to every persistent volume in the cluster. Expect proof-of-concept code to follow quickly given the CVSS 10 rating and the simplicity of a missing-auth bug.

References