Dell asks admins to patch max severity CSM flaws as soon as possible
Dell patched six critical Container Storage Modules flaws that let unauthenticated attackers gain admin control of enterprise storage.
Dell patched six critical flaws in Container Storage Modules, which link PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT arrays to Kubernetes. CVE-2026-63688 and CVE-2026-63692, both missing-authentication bugs in CSM Authorization, let unauthenticated remote attackers steal storage admin credentials or bypass auth and take full administrative control, including across tenants. Four further flaws allow root on cluster nodes (CVE-2026-67269), admin access to the authorization proxy (CVE-2026-54472), forged admin tokens (CVE-2026-61421), and cluster-wide reads of Kubernetes Secrets (CVE-2026-67273). Dell urges an upgrade to version 1.18.0 or later and has not reported active exploitation of these bugs.