Six Dell CSM Flaws Expose Storage Credentials, Tenant Controls, and Kubernetes Nodes
Dell patched six critical CSM flaws, including two CVSS 10.0 bugs enabling credential theft, token forgery, tenant takeover and Kubernetes root access.
Illustrative image generated with AI
Dell has released security updates for six high-impact vulnerabilities in Dell Container Storage Modules (CSM), including two flaws carrying the maximum CVSS score of 10.0.
Depending on the vulnerability, attackers could steal storage-administrator credentials, forge administrative tokens, take control of authorization services, access Kubernetes Secrets, modify cluster-wide access controls, or obtain root privileges on cluster nodes.
The affected components include the csm-authorization-storage gRPC server, authorization proxy, tenant service, ContainerStorageModule Custom Resource reconciler, CSM Authorization module, and the JWT authentication code in karavi-authorization.
According to the report describing Dell’s security updates, versions earlier than 1.17.0 are affected, while the vulnerabilities are addressed in 1.18.0. The report does not clarify the security status of 1.17.0, so administrators should not infer that it is either vulnerable or fixed from those version boundaries alone.
Unauthenticated flaws reach storage administration
The most severe issues provide attack paths that do not require an existing account.
CVE-2026-63688, rated CVSS 10.0, is an authentication failure in the csm-authorization-storage gRPC server. A remote, unauthenticated attacker could use the exposed function to obtain administrator credentials for all registered storage arrays.
Dell characterizes the issue as a complete bypass of the CSM Authorization security model. Successful exploitation could provide full administrative control over storage infrastructure spanning all five Dell storage product families supported by CSM. The cited report does not identify those families individually.
The scope is broader than access to a single volume or tenant. Storage-backend administrator credentials may provide control at the array level, making this vulnerability particularly serious in clusters connected to multiple registered systems.
A second maximum-severity flaw, CVE-2026-63692, affects the authorization proxy and tenant service. It also has a CVSS score of 10.0.
An unauthenticated network attacker could bypass the affected authentication checks and acquire administrative privileges. Dell says exploitation could result in complete control of the authorization service, including the ability to access or manipulate storage resources across all tenants.
The two vulnerabilities affect different trust boundaries. CVE-2026-63688 exposes credentials used to administer storage backends, while CVE-2026-63692 compromises the service responsible for enforcing authorization between tenants and storage resources.
Hard-coded secrets allow attackers to forge tokens
Two additional vulnerabilities concern credentials or cryptographic material embedded in CSM components.
CVE-2026-54472, rated CVSS 9.8, is a hard-coded credential vulnerability in the CSM Authorization module. A remote attacker who is not authenticated could create cryptographically valid administrative tokens and use them against the CSM Authorization proxy.
This would bypass the proxy’s normal authentication controls. The resulting privileges could allow unauthorized management of storage-access policies affecting all connected tenants.
CVE-2026-61421, also rated CVSS 9.8, involves a hard-coded cryptographic key in the JWT authentication component of karavi-authorization. An unauthenticated remote attacker who knows the publicly available signing secret could generate forged authentication tokens and obtain administrative privileges.
These flaws attack the trust placed in signed tokens. If a verifier accepts tokens created with a compromised or publicly known signing secret, the presence of a valid signature no longer proves that an authorized service issued the token.
Updating the software addresses the vulnerable implementation, but Dell also recommends rotating JWT signing secrets. That additional step matters because previously exposed key material should not remain trusted after the upgrade.
Kubernetes privilege escalation can reach every node
The remaining vulnerabilities begin from low-privilege access but can cross major Kubernetes security boundaries.
CVE-2026-67269 is an improper privilege-management vulnerability in the ContainerStorageModule Custom Resource reconciler. It carries a CVSS score of 9.9.
A low-privilege remote attacker could submit a crafted custom resource and escalate to root-level access on cluster nodes. Dell reportedly says that a single custom-resource submission could be sufficient to compromise all nodes in a Kubernetes cluster.
The flaw therefore turns permission to interact with a CSM custom resource into a potential node-level compromise. It also shows why access to Kubernetes custom resources cannot be treated as harmless when privileged controllers reconcile their contents.
CVE-2026-67273, rated CVSS 9.6, results from improper neutralization of special elements processed by a template engine. A low-privilege attacker with remote access could exploit the issue to escalate privileges, retrieve sensitive data, and make unauthorized changes to role-based access control.
Dell says successful exploitation could provide cluster-wide read access to Kubernetes Secrets. It could also permit the creation of cluster-scoped RBAC resources, bypassing the access restrictions that should contain the attacker’s existing identity.
The reported consequences place both flaws beyond the CSM service itself. One can lead to root privileges across nodes, while the other can expose cluster secrets and alter authorization policy throughout the Kubernetes environment.
Version 1.18.0 is the prescribed fix
The reported affected range covers all CSM releases earlier than 1.17.0, and Dell addresses the six vulnerabilities in 1.18.0.
Because the available version information leaves 1.17.0 unresolved, organizations should base remediation on Dell’s fixed release rather than treating 1.17.0 as implicitly safe. The reported guidance is to update to the latest version.
No alternative workaround or mitigation is provided in the cited report. Network restrictions or other defensive controls may reduce exposure in some environments, but they should not be treated as replacements for the vendor update.
Administrators should take the following actions based on the published guidance:
- Inventory deployed Dell CSM versions and identify installations not running 1.18.0.
- Upgrade affected deployments to the fixed release.
- Rotate JWT signing secrets as recommended by Dell.
- Review the privileges granted to identities that can submit ContainerStorageModule custom resources.
- Confirm that authorization services, tenant interfaces, and the
csm-authorization-storagegRPC server are not exposed beyond their operational requirements.
The report does not provide indicators of compromise. Its absence of indicators, however, does not establish that none may have been published through other channels.
Exploitation is not reported for these six CVEs
The available reporting does not state that any of the six CSM vulnerabilities are being exploited in the wild. That distinction matters: the potential impact is severe, but the supplied evidence does not support describing these flaws as confirmed active-exploitation cases.
Dell products have nevertheless appeared in the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog before.
CVE-2026-22769 affects Dell RecoverPoint for Virtual Machines versions before 6.0.3.1 HF1. The hard-coded credential vulnerability has a CVSS score of 10 and can give an unauthenticated remote attacker access to the underlying operating system with root-level persistence.
CISA added CVE-2026-22769 to the KEV catalog on 2026-02-18, with a federal remediation deadline of 2026-02-21. Its required action is: “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”
An older Dell issue, CVE-2021-21551, is an insufficient access-control vulnerability in the dbutil_2_3.sys driver. It requires local authenticated access and can lead to privilege escalation, denial of service, or information disclosure. Its CVSS score is 8.8.
CISA placed CVE-2021-21551 in KEV on 2022-03-31 and set a remediation deadline of 2022-04-21 for affected US federal agencies. The required action was to apply updates according to vendor instructions.
Those earlier KEV entries provide context for Dell’s exposure to actively exploited vulnerabilities, but they are separate from the six CSM flaws. No common attacker, campaign, or exploitation sequence is established by the available information.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-22769Critical10.0Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized acces
- CVE-2021-21551High8.8Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.




