DSA-2026-448: Security Update for Dell Container Storage Modules Multiple Vulnerabilities
Summary: Dell Container Storage Modules remediation is available for Multiple vulnerabilities in third-party that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Critical
Details
| Third-party Component | CVEs | More Information |
|---|---|---|
| golang.org/x/crypto | CVE-2024-45337, CVE-2025-22869, CVE-2025-47913, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598 | http://nvd.nist.gov/ |
| github.com/golang-jwt/jwt/v4 , google.golang.org/protobuf | CVE-2024-51744, CVE-2025-30204, CVE-2024-24786 | http://nvd.nist.gov/ |
| golang.org/x/net | CVE-2026-39821, CVE-2026-33814, CVE-2026-25680, CVE-2025-22870, CVE-2025-22872 | http://nvd.nist.gov/ |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2026-63688 | Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays. This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families. Dell recommends customers to upgrade at the earliest opportunity. | 10.00 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-63692 | Dell Container Storage Modules (CSM) Authorization, version v2.4.0, contain a Missing Authentication for Critical Function vulnerability in the authorization proxy and tenant service. An unauthenticated network attacker could potentially exploit this vulnerability, leading to bypass of authentication controls and unauthorized elevation of privileges to the administrative level. This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants. Dell recommends customers upgrade at the earliest opportunity. | 10.00 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-67269 | Dell Container Storage Modules (CSM) Operator, Version 1.12.0, contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes. This vulnerability is considered critical as it can be leveraged to completely compromise all nodes in the Kubernetes cluster through a single custom resource submission. Dell recommends customers to upgrade at the earliest opportunity. | 9.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-54472 | Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Use of Hard-coded Credentials Vulnerability in the CSM Authorization module. A remote unauthenticated attacker, could potentially exploit this vulnerability to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy. This vulnerability is considered critical as it allows a remote unauthenticated attacker to completely bypass authentication controls for the CSM Authorization proxy, enabling unauthorized management of storage access policies across all connected tenants. Dell recommends customers to upgrade at the earliest opportunity and immediately rotate any JWT signing secrets. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-61421 | Dell Container Storage Modules (CSM) karavi-authorization, which is now archived and no longer actively maintained, contained a Use of Hard-coded Cryptographic Key vulnerability in the JWT authentication component. The official proxy-server configuration documentation demonstrated supersecret as the JWT signing secret alongside real token output; this page was subsequently removed without a security advisory. Any organization that deployed karavi-authorization following this guide and has not rotated the signing secret may remain vulnerable. A remote unauthenticated attacker who knows this publicly available signing secret could forge authentication tokens and gain administrative privileges. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-67273 | Dell Container Storage Modules, version(s) [1.12.0], contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges, information disclosure, and unauthorized RBAC tampering. This is classified as Critical because successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls. | 9.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
| CVE-2026-67270 | Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. | 8.2 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| CVE-2026-76105 | Dell Dell Container Storage Modules, version(s) v1.18.0, contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.7 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| CVE-2026-61411 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | 7.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| CVE-2026-70411 | Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags. | 7.1 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
| CVE-2026-63689 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-63691 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | 6.1 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L |
| CVE-2026-63690 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. | 5.4 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2026-63688 | Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays. This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families. Dell recommends customers to upgrade at the earliest opportunity. | 10.00 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-63692 | Dell Container Storage Modules (CSM) Authorization, version v2.4.0, contain a Missing Authentication for Critical Function vulnerability in the authorization proxy and tenant service. An unauthenticated network attacker could potentially exploit this vulnerability, leading to bypass of authentication controls and unauthorized elevation of privileges to the administrative level. This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants. Dell recommends customers upgrade at the earliest opportunity. | 10.00 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-67269 | Dell Container Storage Modules (CSM) Operator, Version 1.12.0, contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes. This vulnerability is considered critical as it can be leveraged to completely compromise all nodes in the Kubernetes cluster through a single custom resource submission. Dell recommends customers to upgrade at the earliest opportunity. | 9.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-54472 | Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Use of Hard-coded Credentials Vulnerability in the CSM Authorization module. A remote unauthenticated attacker, could potentially exploit this vulnerability to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy. This vulnerability is considered critical as it allows a remote unauthenticated attacker to completely bypass authentication controls for the CSM Authorization proxy, enabling unauthorized management of storage access policies across all connected tenants. Dell recommends customers to upgrade at the earliest opportunity and immediately rotate any JWT signing secrets. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-61421 | Dell Container Storage Modules (CSM) karavi-authorization, which is now archived and no longer actively maintained, contained a Use of Hard-coded Cryptographic Key vulnerability in the JWT authentication component. The official proxy-server configuration documentation demonstrated supersecret as the JWT signing secret alongside real token output; this page was subsequently removed without a security advisory. Any organization that deployed karavi-authorization following this guide and has not rotated the signing secret may remain vulnerable. A remote unauthenticated attacker who knows this publicly available signing secret could forge authentication tokens and gain administrative privileges. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-67273 | Dell Container Storage Modules, version(s) [1.12.0], contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges, information disclosure, and unauthorized RBAC tampering. This is classified as Critical because successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls. | 9.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
| CVE-2026-67270 | Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. | 8.2 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| CVE-2026-76105 | Dell Dell Container Storage Modules, version(s) v1.18.0, contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | 7.7 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| CVE-2026-61411 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | 7.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| CVE-2026-70411 | Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags. | 7.1 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
| CVE-2026-63689 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | 6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-63691 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | 6.1 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L |
| CVE-2026-63690 | Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. | 5.4 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Affected Products & Remediation
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Container storage modules | Versions prior to 1.17.0 | Version 1.18.0 or later | https://eos2git.cec.lab.emc.com/Ecosystems/container-storage-modules |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Container storage modules | Versions prior to 1.17.0 | Version 1.18.0 or later | https://eos2git.cec.lab.emc.com/Ecosystems/container-storage-modules |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Workarounds & Mitigations
None
Revision History
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-10-01 | Initial Release |
Related Information
Legal Disclaimer
Affected Products
Container Storage ModulesArticle Properties
Article Number: 000515771
Article Type: Dell Security Advisory
Last Modified: 01 Oct 2026
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.