Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control
Dell patched multiple critical Container Storage Module flaws, including two CVSS 10.0 bugs that let unauthenticated attackers seize administrative control.
Dell published DSA-2026-448 for critical flaws in Container Storage Modules before 1.17.0, fixed in 1.18.0 and later. CVE-2026-63688 and CVE-2026-63692, both CVSS 10.0, let unauthenticated attackers reach CSM Authorization 2.4.0 admin functions and storage-array credentials across Dell's supported families. CVE-2026-54472 (CVSS 9.8) uses hard-coded credentials to forge administrative JWTs, while CVE-2026-67269 (CVSS 9.9) and CVE-2026-67273 (CVSS 9.6) can yield Kubernetes node root or cluster RBAC abuse. Dell said no workarounds exist and advised upgrading, rotating JWT secrets, and reviewing authorization logs and RBAC.