Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)

Dell Container Storage Modules (CSM) flaws enable (TL-2026-2851), also tracked as DSA-2026-448, is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-02. It has no confirmed attribution, affects Dell Container Storage Modules (CSM), references 6 CVEs (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269), maps to 10 MITRE ATT&CK techniques (T1078, T1078.001, T1098), and is covered by 9 detection rules and 8 indicators of compromise.

Key facts for TL-2026-2851

Threat ID
TL-2026-2851
Also known as
DSA-2026-448
Severity
CRITICAL
CVSS
10
Status
PATCHED
Category
VULNERABILITY
First published
2026-10-02
Last reviewed
2026-10-02
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, health, government administration, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
8

Dell advisory DSA-2026-448 (2026-10-01) fixes six critical flaws (CVSS 9.6-10.0) in Dell Container Storage Modules: missing authentication in the csm-authorization-storage gRPC server and the authorization proxy/tenant service, hard-coded credentials and a hard-coded JWT signing key enabling forged admin tokens, improper privilege management in the CSM Operator custom resource reconciler giving root on cluster nodes, and a template engine injection enabling cluster-wide Secret reads and RBAC tampering. Fixed in CSM 1.18.0; no in-the-wild exploitation or public PoC was reported at publication.

How Dell Container Storage Modules (CSM) flaws enable works

Dell Container Storage Modules (CSM) is the software layer that connects Dell storage arrays (PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT) to Kubernetes clusters. On 2026-10-01 Dell published DSA-2026-448 covering six vulnerabilities, reported on 2026-10-02 by The Hacker News and several secondary outlets.

CVE-2026-63688 (CVSS 10.0) is a missing-authentication flaw in the csm-authorization-storage gRPC server. An unauthenticated remote attacker who can reach the service can obtain storage-backend administrator credentials for all registered storage arrays, which bypasses the csm-authorization security model and gives full administrative control across all five supported Dell storage families. One secondary source maps it to CWE-863. CVE-2026-63692 (CVSS 10.0) is a missing-authentication flaw in the authorization proxy and tenant service. An unauthenticated network attacker can bypass login checks and gain administrative privileges, including reading and altering storage resources across all tenants.

CVE-2026-54472 (CVSS 9.8) is a hard-coded-credentials flaw in the CSM authorization proxy that lets a remote attacker forge cryptographically valid administrative tokens. CVE-2026-61421 (CVSS 9.8) is a hard-coded cryptographic key in the archived karavi-authorization project: a sample JWT signing secret published in the setup documentation lets an unauthenticated attacker forge authentication tokens against deployments that kept the sample value. Mitigation therefore includes rotating JWT signing secrets and retiring karavi-authorization deployments.

CVE-2026-67269 (CVSS 9.9) is an improper-privilege-management flaw in the ContainerStorageModule custom resource reconciler of the CSM Operator. A low-privileged user who can submit a single custom resource can obtain root-level access on cluster nodes, and so potentially compromise every node in the Kubernetes cluster. CVE-2026-67273 (CVSS 9.6) is a template engine injection flaw that lets a low-privileged remote attacker escalate privileges, tamper with RBAC and read Kubernetes Secrets cluster-wide.

Affected: CSM prior to 1.17.0 per Dell-derived reporting (one outlet says 'before 1.18.0'; the boundary is inconsistent across sources). Fixed in CSM 1.18.0 (components cited: CSM Authorization 2.4.0, CSM Operator 1.12.0); the release also updates the third-party dependencies golang.org/x/crypto, golang.org/x/net, golang-jwt and protobuf. No workarounds are listed beyond patching. Secondary reporting advises restricting network access to CSM services to cluster-internal sources, rotating storage administrator credentials and JWT signing secrets, auditing Secret access logs, admin sessions and RBAC role changes, and retiring karavi-authorization. No in-the-wild exploitation or public proof of concept was reported at publication, though one outlet warns that CVSS 10 flaws like these are quickly reverse-engineered from patches. A related earlier advisory, DSA-2026-234 (2026-05-21, CVE-2026-40710, CVSS 10.0, hard-coded default credentials in CSM Operator 1.6.0-1.16.3 and Helm Charts 1.11.0-1.16.3, fixed in 1.17.0), shows the same product line has a recent history of hard-coded credential exposure.

MITRE ATT&CK techniques used in TL-2026-2851

Initial Access

T1078 Valid Accounts; T1078.001 Valid Accounts: Default Accounts; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation

Privilege Escalation

T1548 Abuse Elevation Control Mechanism; T1611 Escape to Host

lateral-movement

T1550 Use Alternate Authentication Material

Credential Access

T1552 Unsecured Credentials; T1552.007 Unsecured Credentials: Container API; T1606 Forge Web Credentials

Affected products and versions in Dell Container Storage Modules (CSM) flaws enable

  • Dell — Container Storage Modules (CSM)
    Vulnerable versions: prior to 1.17.0 (one source: prior to 1.18.0)
    Fixed in: 1.18.0
  • Dell — CSM Authorization / karavi-authorization (archived)
    Vulnerable versions: CSM Authorization prior to 2.4.0 and archived karavi-authorization sample JWT secret
    Fixed in: 2.4.0
  • Dell — CSM Operator
    Vulnerable versions: prior to 1.12.0
    Fixed in: 1.12.0

Remediation for Dell Container Storage Modules (CSM) flaws enable

Patches

  • Dell DSA-2026-448: CSM 1.18.0 (CSM Authorization 2.4.0, CSM Operator 1.12.0)

Immediate actions

  • Upgrade Dell Container Storage Modules to 1.18.0 or later (DSA-2026-448)
  • Rotate JWT signing secrets used by CSM Authorization
  • Replace storage backend administrator credentials for all registered arrays
  • Restrict network access to CSM authorization proxy, tenant service and csm-authorization-storage gRPC endpoints to cluster-internal sources

Workarounds

  • No workarounds beyond patching are listed by the sources; network restriction reduces exposure

Longer-term hardening

  • Retire karavi-authorization (archived/deprecated) and migrate to CSM Authorization v2
  • Audit Kubernetes Secret access logs, storage admin sessions and RBAC role changes for tampering
  • Restrict who can create or modify ContainerStorageModule custom resources

CVEs associated with Dell Container Storage Modules (CSM) flaws enable

CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273

Weaknesses (CWE) in Dell Container Storage Modules (CSM) flaws enable

CWE-306, CWE-863, CWE-798, CWE-321, CWE-269, CWE-1336

Timeline of Dell Container Storage Modules (CSM) flaws enable

  • Dell archives the dell/karavi-authorization GitHub repository (CSM Authorization v1) as read-only and deprecated in favour of CSM Authorization v2; the project later becomes the source of the CVE-2026-61421 sample JWT secret exposure.
  • Dell publishes DSA-2026-234 for CVE-2026-40710 (CVSS 10.0), hard-coded default credentials in CSM Operator 1.6.0-1.16.3 and Helm Charts 1.11.0-1.16.3, fixed in 1.17.0; related earlier credential exposure in the same product line.
  • Dell releases CSM 1.18.0 (CSM Authorization 2.4.0, CSM Operator 1.12.0) fixing the flaws and updating golang.org/x/crypto, golang.org/x/net, golang-jwt and protobuf.
  • Dell publishes DSA-2026-448 covering six CSM vulnerabilities: CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421 and CVE-2026-67273 (CVSS 9.6-10.0).
  • No in-the-wild exploitation or public proof-of-concept reported at publication; one outlet warns that CVSS 10 flaws are typically reverse-engineered from patches within days.
  • Secondary reporting states DSA-2026-448 covers 24 CVEs in total (9 critical, 9 high, 5 medium, 1 low); Dell notes version tables may be incomplete and that earlier Dell flaws (CVE-2021-21551, CVE-2026-22769) were exploited.
  • The Hacker News and other outlets publish analyses of the Dell CSM flaws and advise rotating JWT signing secrets and restricting network access to CSM services.

Sources cited for Dell Container Storage Modules (CSM) flaws enable

More in vulnerability

Detection coverage for TL-2026-2851

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2851 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats