Dell Issues Critical Security Updates for Container Storage Modules; Urges Immediate Upgrade

October 2, 2026
Dell Issues Critical Security Updates for Container Storage Modules; Urges Immediate Upgrade
  • Dell has released security updates for Dell Container Storage Modules (CSM) to fix critical vulnerabilities that could allow unauthenticated access or privilege escalation on Kubernetes nodes and storage infrastructure.

  • All CSM versions prior to 1.17.0 are affected; the fixes are available in version 1.18.0, with Dell stating there are no workarounds other than upgrading.

  • CVE-2026-63692 carries a CVSS of 10.0 and could let an unauthenticated attacker bypass authentication and gain admin privileges through the authorization proxy and tenant service.

  • CVE-2026-67273 has a CVSS of 9.6 and involves improper neutralization of elements in a template engine, allowing a low-privilege attacker with remote access to escalate privileges, access sensitive data, and tamper RBAC.

  • Dell notes that exploitation could grant cluster-wide read access to Kubernetes Secrets and enable creation of cluster-scoped RBAC resources, effectively bypassing Kubernetes access controls.

  • Dell urges users to upgrade to the latest CSM release and to rotate JWT signing secrets to mitigate risk.

  • CVE-2026-54472 has a CVSS of 9.8 and stems from hard-coded credentials in the CSM Authorization module, enabling forging of admin tokens and unauthorized access to the authorization proxy.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories