Skip to content
Security & Trust

Dell storage flaws expose storage controls and, in some cases, Kubernetes nodes

Six flaws in Dell Container Storage Modules score 9.6 to 10.0. Updating is the only fix Dell offers.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Dell storage flaws expose storage controls and, in some cases, Kubernetes nodes

AI-generated image for WebPulse. About our images

In brief
  • Dell patched six flaws in Container Storage Modules, scoring 9.6 to 10.0. Four sit in the authorization layer. Two, CVE-2026-67269 and CVE-2026-67273, let low-privilege attackers escalate inside Kubernetes.
  • Dell says CVE-2026-63692 could expose storage resources across all tenants. The report names no fix other than updating to CSM 1.18.0.
  • Find where CSM runs, confirm the version, rotate JWT signing secrets, and review who can submit custom resources.

One lock on many doors saves effort. It also means one flaw opens them all. Dell's latest security update shows what that costs.

Dell has fixed six serious flaws in Dell Container Storage Modules (CSM). CSM links Kubernetes clusters to Dell storage arrays. The Hacker News reported the advisories on October 2, 2026. Two flaws score 10.0 on CVSS, a standard severity scale. The other four score 9.9, 9.8, 9.8 and 9.6.

One gatekeeper, every tenant

Four of the flaws sit in the authorization part of CSM. This layer decides who may manage storage. Dell says CVE-2026-63688 allows "a complete bypass of the csm-authorization security model." An attacker could then take full control of storage. That covers all five supported Dell storage product families.

CVE-2026-63692 hits the authorization proxy and tenant service. Dell says an attacker with no login could take over the authorization service. The attacker could then read or change storage belonging to every tenant. A tenant is a separate team or customer sharing the system.

This shows the cost of a shared gatekeeper. One policy and one place to audit is efficient. But one failure exposes everyone behind it. Teams that run many business units on shared storage carry that concentration.

6 CVEs, CVSS 9.6 to 10.0
Flaws patched in this Dell CSM release
Source: Dell advisories as reported by The Hacker News (October 2, 2026)

How the authorization flaws work

Two of the four are missing-authentication flaws. A function that should ask for credentials does not. CVE-2026-63688 is in a gRPC server, a service that other programs call over the network. Dell says a remote attacker with no login could get administrator credentials for all registered storage arrays.

The other two involve secrets built into the software. CVE-2026-54472 is a hard-coded credentials flaw. An attacker could use it to forge valid administrator tokens for the CSM Authorization proxy.

CVE-2026-61421 is a hard-coded cryptographic key in the JWT component of karavi-authorization. A JWT is a signed digital pass that proves who you are. If the signing secret is public, anyone can forge a pass. Dell advises rotating JWT signing secrets along with the update.

10.0 (CVE-2026-63688 and CVE-2026-63692)
Highest severity scores
Source: Dell advisories as reported by The Hacker News (October 2, 2026)

A second risk: reach inside the cluster

The last two flaws are not about the authorization layer. They are about escalation inside Kubernetes. Dell says both need only a low-privilege attacker.

CVE-2026-67269 is in the reconciler for the ContainerStorageModule custom resource. A reconciler is code that turns a settings object into real changes. Dell says an attacker could gain root-level access on cluster nodes. Dell also says a single custom resource submission could compromise every node in a cluster.

CVE-2026-67273 is a template engine flaw. Dell says it gives read access to Kubernetes Secrets across the whole cluster. Secrets hold passwords and keys. It also lets an attacker create cluster-wide RBAC resources. RBAC is the system that sets who can do what in Kubernetes. Dell says this effectively bypasses the intended access controls.

These two flaws teach a different lesson. Software that can act on a whole cluster turns a small foothold into a large one. That risk is separate from the shared gatekeeper.

What the report does not say

The report does not say anyone is exploiting these six flaws. It does note that two older Dell flaws, CVE-2021-21551 and CVE-2026-22769, have been exploited in recent years. That is context. It is not evidence about this release.

The version wording leaves a gap. The report says all versions before 1.17.0 are affected. It says 1.18.0 contains the fixes. It does not say how 1.17.0 itself is treated. Confirm the exact fixed version in Dell's own advisories.

Dell names no workaround other than the update. A team that cannot update soon has nothing else from Dell to use.

CSM 1.18.0
Fixed version named by Dell
Source: Dell advisories as reported by The Hacker News (October 2, 2026)

What leaders should ask their teams

First, ask whether the company runs Dell CSM anywhere. Include clusters owned by single business units. Shared storage tools are easy to lose track of.

Second, ask which version is running and when it will reach the fixed release. The patch is the main control.

Third, ask whether JWT signing secrets have been rotated. Dell recommends it. An update alone does not change a secret that may already be known.

Fourth, ask who can submit custom resources to those clusters. Dell says a low-privilege attacker could reach the node-level flaw.

Fifth, ask for a review of the storage administrator credentials and Kubernetes Secrets that these components could reach.

A shared gatekeeper earns its place only if it holds. And software that can act on a whole cluster should answer to very few people.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Hacker News.

Share this insight