Dell CSM: two CVSS 10 auth-bypass flaws, patch to 1.18.0
Dell's DSA-2026-448 fixes two maximum-severity authentication-bypass bugs in Container Storage Modules that hand attackers full admin control of storage backends. Fixed in CSM 1.18.0.
Dell shipped DSA-2026-448 on October 1, patching multiple flaws in Container Storage Modules (CSM) — the software that bridges Dell enterprise arrays to Kubernetes. Two of them carry CVSS 10.0. An unauthenticated attacker who can reach the CSM services gets full administrative control of the storage backend for every registered array.
Affected versions
CSM prior to 1.17.0, across PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT deployments. Fixed in 1.18.0. Per Dell's advisory, there is no partial mitigation short of the upgrade for the two 10.0 bugs.
The flaws
Six of the issues are critical:
- CVE-2026-63688 (CVSS 10.0) — missing authentication in the
csm-authorization-storagegRPC server. Lets an unauthenticated remote attacker read storage-backend admin credentials for all registered arrays and bypass authorization for full admin control. - CVE-2026-63692 (CVSS 10.0) — missing authentication in the authorization proxy and tenant service; admin privileges by auth bypass.
- CVE-2026-67269 (CVSS 9.9) — improper privilege management in CSM Operator; root on cluster nodes.
- CVE-2026-54472 (CVSS 9.8) — hard-coded credentials granting admin access to the CSM authorization proxy.
- CVE-2026-61421 (CVSS 9.8) — hard-coded cryptographic key in the archived
karavi-authorizationcomponent; forged authentication tokens. - CVE-2026-67273 (CVSS 9.6) — template-engine injection; bypass of Kubernetes access controls for cluster-wide read of Secrets.
The common thread is authentication that was never there: missing checks on a gRPC listener, credentials and keys baked into shipped code. The all-arrays blast radius on CVE-2026-63688 is what earns the 10.0 — one reachable endpoint, every backend.
Exploitation status
Dell lists no in-the-wild exploitation. There is no public PoC at the time of writing. That is the window: a CVSS 10 unauthenticated auth bypass in storage-control-plane software is exactly the class that gets reverse-engineered from the patch within days.
Action checklist
- Upgrade CSM to 1.18.0 or later on every cluster — treat the two 10.0 bugs as patch-now.
- Until you patch, restrict network reach to the CSM authorization and gRPC services to known cluster-internal sources only; do not expose them beyond the Kubernetes control plane.
- Rotate storage-backend administrator credentials for any array managed by a pre-1.18.0 CSM — the hard-coded-credential and key-disclosure bugs mean secrets may already be derivable.
- Audit Kubernetes Secrets access logs and array admin sessions for the exposure window.
Context
Dell storage and data-protection products have been a recurring target: flaws in Dell infrastructure have drawn state-sponsored interest before, and storage control planes sit upstream of everything they serve. An auth bypass here isn't a data-exposure footnote — it's admin over the arrays holding production data. Patch state on CSM is now part of your cluster's trust boundary.