Dell CSM vulnerabilities let unauthenticated attackers gain admin access
According to BleepingComputer, Dell patched multiple maximum-severity flaws in its Container Storage Modules that let unauthenticated attackers gain admin access, and recommends updating to CSM 1.18.0 or later.
Dell released patches for multiple maximum-severity issues in its Container Storage Modules, the components that tie Dell enterprise storage arrays into Kubernetes environments, according to BleepingComputer. The advisory covers two maximum-severity authorization flaws plus four other critical issues, and Dell recommends customers upgrade to CSM version 1.18.0 or later, BleepingComputer reports.
What changed and why it matters
According to BleepingComputer, the two maximum-severity bugs are in the Dell CSM Authorization security module and stem from missing authentication for critical functions. One of those flaws, tracked as CVE-2026-63688, can let unauthenticated remote attackers obtain storage backend administrator credentials for all registered storage arrays. The other high-impact issue, CVE-2026-63692, can let attackers bypass authentication controls in the authorization proxy and tenant service to gain admin privileges.
These problems affect the Container Storage Modules that integrate Dell platforms including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT with Kubernetes. That means if your infrastructure uses Dell storage through CSM, an attacker who can reach the affected services could potentially control storage resources across tenants, the advisory warns, according to BleepingComputer.
Additional critical issues Dell patched
BleepingComputer says Dell also fixed four other critical CSM flaws: one that allows remote attackers to gain root on cluster nodes, one that permits administrative access to the CSM authorization proxy, one that enables forging of authentication tokens to obtain admin privileges, and one that bypasses Kubernetes access controls to read Kubernetes Secrets cluster-wide. Dell has issued patches for all of these and grouped them in the same update.
Context: why past Dell bugs matter
BleepingComputer notes Dell systems have been targeted by state-sponsored groups in prior incidents, where other Dell vulnerabilities were abused to deploy malware or gain persistent access. The article points to earlier cases where attackers exploited Dell driver or product flaws to install rootkits or create hidden network interfaces. That history is part of why Dell is urging rapid updates in this case, according to BleepingComputer.
Immediate steps you should take
Follow these practical steps now, in order of priority:
- Patch CSM to version 1.18.0 or later, per Dell's advisory reported by BleepingComputer.
- If you cannot patch immediately, isolate or restrict network access to the CSM services so they are not reachable from untrusted networks.
- Review who has administrative credentials for storage backends and the CSM authorization service, and remove unnecessary privileges.
- Rotate any exposed or high-risk credentials tied to storage arrays and tenant services after applying updates.
- Check Kubernetes role bindings and Secrets access policies to ensure only required services and users have read rights.
- After patching, monitor logs for unexpected authentication bypass attempts or token forging activity.
If you want to know how exposed your own site is, start with a free external scan on our security page: /security.html.
What to monitor after you patch
After you apply the updates, keep an eye on several areas for signs of prior or ongoing abuse. Look for unusual admin logins, unexplained credential changes, creation of new service accounts, or unexpected network interfaces on storage hosts. Because some of the issues allow token forgery or cluster-wide secret reads, focus on unusual access to Kubernetes Secrets and any processes that request elevated authorization.
Document the changes you make, and if you find evidence of compromise, follow your incident response procedures. That includes isolating affected hosts, collecting forensic logs, and rotating credentials that might have been exposed.
Practical takeaways for small teams and nonprofits
If your organization uses Dell enterprise storage with Kubernetes, these issues should be treated as high priority. The vulnerabilities allow unauthenticated actors to gain elevated access, which can lead to data exposure or destruction. Even small teams should plan for rapid testing and deployment of patches, limit who can reach their CSM services over the network, and review administrative privileges.
BleepingComputer reports Dell's recommendation to update to CSM 1.18.0 or later. Apply that update as soon as you can and verify that the patched services behave as expected. If you do not directly manage the storage or CSM, contact your provider or hosting team and confirm they have applied the fixes.
If you need a quick initial check of external exposure, start with a free external scan on our security page: /security.html.
Sources
- Dell asks admins to patch max severity CSM flaws as soon as possible BleepingComputer
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.