DSA-2026-448: Security Update for Dell Container Storage Modules Multiple Vulnerabilities

Summary: Dell Container Storage Modules remediation is available for Multiple vulnerabilities in third-party that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

Third-party Component CVEs More Information
golang.org/x/crypto CVE-2024-45337, CVE-2025-22869, CVE-2025-47913, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598 http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
github.com/golang-jwt/jwt/v4 , google.golang.org/protobuf CVE-2024-51744, CVE-2025-30204, CVE-2024-24786 http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.
golang.org/x/net CVE-2026-39821, CVE-2026-33814, CVE-2026-25680, CVE-2025-22870, CVE-2025-22872 http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-63688 Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays. This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families. Dell recommends customers to upgrade at the earliest opportunity. 10.00 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-63692 Dell Container Storage Modules (CSM) Authorization, version v2.4.0, contain a Missing Authentication for Critical Function vulnerability in the authorization proxy and tenant service. An unauthenticated network attacker could potentially exploit this vulnerability, leading to bypass of authentication controls and unauthorized elevation of privileges to the administrative level. This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants. Dell recommends customers upgrade at the earliest opportunity. 10.00 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-67269 Dell Container Storage Modules (CSM) Operator, Version 1.12.0, contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes. This vulnerability is considered critical as it can be leveraged to completely compromise all nodes in the Kubernetes cluster through a single custom resource submission. Dell recommends customers to upgrade at the earliest opportunity. 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-54472 Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Use of Hard-coded Credentials Vulnerability in the CSM Authorization module. A remote unauthenticated attacker, could potentially exploit this vulnerability to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy. This vulnerability is considered critical as it allows a remote unauthenticated attacker to completely bypass authentication controls for the CSM Authorization proxy, enabling unauthorized management of storage access policies across all connected tenants. Dell recommends customers to upgrade at the earliest opportunity and immediately rotate any JWT signing secrets. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-61421 Dell Container Storage Modules (CSM) karavi-authorization, which is now archived and no longer actively maintained, contained a Use of Hard-coded Cryptographic Key vulnerability in the JWT authentication component. The official proxy-server configuration documentation demonstrated supersecret as the JWT signing secret alongside real token output; this page was subsequently removed without a security advisory. Any organization that deployed karavi-authorization following this guide and has not rotated the signing secret may remain vulnerable. A remote unauthenticated attacker who knows this publicly available signing secret could forge authentication tokens and gain administrative privileges. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-67273 Dell Container Storage Modules, version(s) [1.12.0], contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges, information disclosure, and unauthorized RBAC tampering. This is classified as Critical because successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls. 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVE-2026-67270 Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. 8.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
CVE-2026-76105 Dell Dell Container Storage Modules, version(s) v1.18.0, contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVE-2026-61411 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2026-70411 Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags. 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CVE-2026-63689 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2026-63691 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. 6.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
CVE-2026-63690 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-63688 Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays. This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families. Dell recommends customers to upgrade at the earliest opportunity. 10.00 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-63692 Dell Container Storage Modules (CSM) Authorization, version v2.4.0, contain a Missing Authentication for Critical Function vulnerability in the authorization proxy and tenant service. An unauthenticated network attacker could potentially exploit this vulnerability, leading to bypass of authentication controls and unauthorized elevation of privileges to the administrative level. This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants. Dell recommends customers upgrade at the earliest opportunity. 10.00 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-67269 Dell Container Storage Modules (CSM) Operator, Version 1.12.0, contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes. This vulnerability is considered critical as it can be leveraged to completely compromise all nodes in the Kubernetes cluster through a single custom resource submission. Dell recommends customers to upgrade at the earliest opportunity. 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-54472 Dell Container Storage Modules (CSM) Authorization, version 2.4.0, contains a Use of Hard-coded Credentials Vulnerability in the CSM Authorization module. A remote unauthenticated attacker, could potentially exploit this vulnerability to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy. This vulnerability is considered critical as it allows a remote unauthenticated attacker to completely bypass authentication controls for the CSM Authorization proxy, enabling unauthorized management of storage access policies across all connected tenants. Dell recommends customers to upgrade at the earliest opportunity and immediately rotate any JWT signing secrets. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-61421 Dell Container Storage Modules (CSM) karavi-authorization, which is now archived and no longer actively maintained, contained a Use of Hard-coded Cryptographic Key vulnerability in the JWT authentication component. The official proxy-server configuration documentation demonstrated supersecret as the JWT signing secret alongside real token output; this page was subsequently removed without a security advisory. Any organization that deployed karavi-authorization following this guide and has not rotated the signing secret may remain vulnerable. A remote unauthenticated attacker who knows this publicly available signing secret could forge authentication tokens and gain administrative privileges. 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2026-67273 Dell Container Storage Modules, version(s) [1.12.0], contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges, information disclosure, and unauthorized RBAC tampering. This is classified as Critical because successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls. 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVE-2026-67270 Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. 8.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
CVE-2026-76105 Dell Dell Container Storage Modules, version(s) v1.18.0, contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVE-2026-61411 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2026-70411 Dell Container Storage Modules (CSM) Authorization, Version 2.4.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags. 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CVE-2026-63689 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2026-63691 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. 6.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
CVE-2026-63690 Dell Dell Container Storage Modules, version(s) [Versions], contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Remediated Versions Link
Container storage modules  Versions prior to 1.17.0  Version  1.18.0 or later https://eos2git.cec.lab.emc.com/Ecosystems/container-storage-modules 
Product Affected Versions Remediated Versions Link
Container storage modules  Versions prior to 1.17.0  Version  1.18.0 or later https://eos2git.cec.lab.emc.com/Ecosystems/container-storage-modules 

The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available. 

Workarounds & Mitigations

None

Revision History

"

RevisionDateDescription
1.02026-10-01Initial Release

Related Information

Affected Products

Container Storage Modules
Article Properties
Article Number: 000515771
Article Type: Dell Security Advisory
Last Modified: 01 Oct 2026
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.