Vulnerability
Published 2026-10-01
Verified 2026-10-02

Dell CSM DSA-2026-448 (1 Oct): CVE-2026-63688/63692 CVSS 10.0 unauth storage-admin takeover — patch CSM 1.18.0+

Dell Security Advisory DSA-2026-448 (article 000515771; initial release 1 October 2026) patches multiple critical flaws in Dell Container Storage Modules (CSM), which connect Dell PowerStore/PowerScale/PowerFlex/PowerMax/Unity XT arrays to Kubernetes via CSI. Headline proprietary issues in CSM Authorization 2.4.0: CVE-2026-63688 (CVSS 3.1 10.0; AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) missing authentication on the csm-authorization-storage gRPC server lets an unauthenticated remote attacker obtain storage-backend administrator credentials for all registered arrays and fully bypass the CSM authorization model; CVE-2026-63692 (CVSS 10.0, same vector) missing authentication on the authorization proxy/tenant service enables unauthenticated elevation to administrative control across tenants. Same advisory also covers CVE-2026-67269 (CVSS 9.9) CSM Operator 1.12.0 privilege escalation to root on cluster nodes; CVE-2026-54472 (9.8) hard-coded credentials enabling forged admin tokens; CVE-2026-61421 (9.8) archived karavi-authorization JWT demo secret ("supersecret"); CVE-2026-67273 (9.6) template-engine issue granting cluster-wide Secrets read / RBAC tamper; plus additional High/Medium issues. Affected: CSM versions prior to 1.17.0. Remediated: CSM 1.18.0 or later. No workarounds. Dell has not reported active exploitation of these CSM flaws. Primary: Dell DSA-2026-448; wire: BleepingComputer 2 Oct.

Product
Dell Container Storage Modules (CSM) — Authorization, Operator, CSI drivers for PowerStore/PowerScale/PowerFlex/PowerMax/Unity XT
Versions
Affected: Container Storage Modules versions prior to 1.17.0 (Authorization module called out at 2.4.0; Operator at 1.12.0 in CVE text). Fixed: CSM 1.18.0 or later. Rotate JWT signing secrets if Authorization/karavi deployments used documented demo secrets.
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade Dell Container Storage Modules to 1.18.0 or later per DSA-2026-448. Rotate JWT signing secrets for CSM Authorization / any legacy karavi-authorization deployments that followed the documented "supersecret" example. No vendor workaround.

Primary: Dell DSA-2026-448 — CSM multiple vulnerabilities (1 Oct 2026; article 000515771) · Vendor: Dell Technologies Security Advisory DSA-2026-448 · CVE: CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273 · BleepingComputer — Dell asks admins to patch max-severity CSM flaws (2 Oct 2026)

vulnerabilities cloud network