Dell patches critical Container Storage Module vulnerabilities affecting Kubernetes storage
Dell has patched two maximum-severity vulnerabilities in its Container Storage Module (CSM), which connects Dell enterprise storage arrays to Kubernetes environments.
Dell CSM supports the company’s primary storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. It extends the functionality of standard Container Storage Interface (CSI) drivers for Kubernetes.
In a security advisory published Thursday, Dell said both critical flaws were discovered in the Dell CSM Authorization security module. The vulnerabilities resulted from a weakness involving “missing authorization for a critical function.”
Critical Dell CSM flaws enable administrative access
The first vulnerability, tracked as CVE-2026-63688, allows an unauthenticated remote attacker to access storage backend administrator credentials for all registered storage arrays, bypass authorization controls, and gain full administrative control over the storage infrastructure.
Successful exploitation of the second flaw, CVE-2026-63692, in the Authorization Proxy and Tenant service also allows an attacker to bypass authentication controls and obtain administrative privileges.
“This vulnerability is considered critical because it could allow an unauthenticated attacker to gain complete administrative control over the authentication service, potentially allowing unauthorized access and manipulation of storage resources across all tenants,” Dell warned.
Dell also patched four additional high-severity CSM vulnerabilities. These flaws could allow a remote, unprivileged attacker to:
- Gain root privileges on a cluster node through CVE-2026-67269.
- Gain administrative access to the CSM authentication proxy through CVE-2026-54472.
- Forge authentication tokens to obtain administrative privileges through CVE-2026-61421.
- Bypass Kubernetes access controls and obtain cluster-wide read access to Kubernetes Secrets through CVE-2026-67273.
“Dell recommends that customers upgrade at the earliest opportunity,” the company added. Customers should update their Container Storage Modules to version 1.18.0 or later to address the vulnerabilities.
Other Dell vulnerabilities exploited in the wild
Dell has not yet flagged these CSM vulnerabilities as actively exploited. However, state-sponsored hackers have exploited other Dell vulnerabilities in attacks in recent years.
For example, North Korea’s Lazarus hacking group exploited an insufficient access control vulnerability, CVE-2021-21551, in the Dell dbutil driver to deploy a Windows rootkit on victim systems.
More recently, in February, Mandiant and the Google Threat Intelligence Group (GTIG) reported that a suspected Chinese state-sponsored hacking group, tracked as UNC6201, had been exploiting the maximum-severity hardcoded credentials vulnerability CVE-2026-22769 in Dell RecoverPoint for Virtual Machines since at least mid-2024.
The attackers used the vulnerability to deploy malware payloads and access hidden networks on VMware ESXi servers.
Security researchers also found overlap between UNC6201 and Silk Typhoon, a Chinese cyber-espionage group known for targeting government agencies with custom Spawnant and Zipline malware during the Ivanti zero-day attacks.
Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch vulnerable Dell systems on their networks within three days.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



