Dell Issues Critical Security Updates for Container Storage Modules; Urges Immediate Upgrade
October 2, 2026
Dell has released security updates for Dell Container Storage Modules (CSM) to fix critical vulnerabilities that could allow unauthenticated access or privilege escalation on Kubernetes nodes and storage infrastructure.
All CSM versions prior to 1.17.0 are affected; the fixes are available in version 1.18.0, with Dell stating there are no workarounds other than upgrading.
CVE-2026-63692 carries a CVSS of 10.0 and could let an unauthenticated attacker bypass authentication and gain admin privileges through the authorization proxy and tenant service.
CVE-2026-67273 has a CVSS of 9.6 and involves improper neutralization of elements in a template engine, allowing a low-privilege attacker with remote access to escalate privileges, access sensitive data, and tamper RBAC.
Dell notes that exploitation could grant cluster-wide read access to Kubernetes Secrets and enable creation of cluster-scoped RBAC resources, effectively bypassing Kubernetes access controls.
Dell urges users to upgrade to the latest CSM release and to rotate JWT signing secrets to mitigate risk.
CVE-2026-54472 has a CVSS of 9.8 and stems from hard-coded credentials in the CSM Authorization module, enabling forging of admin tokens and unauthorized access to the authorization proxy.
Summary based on 1 source
Get a daily email with more Tech stories
Source

The Hacker News • Oct 2, 2026
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes