Dell has patched three critical vulnerabilities in Container Storage Modules (CSM), the software that connects Kubernetes clusters to Dell storage arrays. Two are rated CVSS 10.0. The third is rated 9.9. The disclosure was reported by The Hacker News and SC Media on 2 October 2026.
The two maximum-severity flaws are authentication failures. CVE-2026-63688 is a missing-authentication flaw in the csm-authorization-storage gRPC server in CSM Authorization 2.4.0. An unauthenticated attacker could retrieve administrator credentials for every registered storage array. CVE-2026-63692 sits in the authorization proxy and tenant service, where login checks are skipped. An attacker could take over the authorization service and then read or alter storage resources belonging to every tenant.
The third flaw, CVE-2026-67269 (CVSS 9.9), affects the CSM Operator's custom resource reconciler. Per the reporting, a single custom resource submitted by a low-privileged user could lead to root access on every node.
Why it matters. The authorization service sits in front of the storage arrays. Taking it over turns one unauthenticated request into administrative reach across multiple tenants and array families. The operator flaw turns a low-privileged Kubernetes foothold into node-level root. Storage credentials and node access are both high-value targets after an initial compromise.
The sources reviewed do not report active exploitation. Dell has asked administrators to patch as soon as possible.
Mitigation. Update Dell Container Storage Modules to the fixed release, reported as 1.18.0 or later, per Dell's advisory. Confirm the exact affected and fixed versions against the advisory before rollout. Until patched, restrict network access to the CSM authorization gRPC and proxy endpoints. Limit who can create custom resources handled by the CSM Operator. Audit Kubernetes RBAC for low-privileged accounts that can submit them. Rotate storage array administrator credentials if the authorization service was reachable from untrusted networks.






























