Dell patches two max severity flaws in Container Storage Modules
Dell has fixed two maximum severity vulnerabilities in its Container Storage Modules (CSM) Authorization module, which links Dell enterprise storage arrays to Kubernetes. Both stem from missing authentication for critical functions and let unauthenticated attackers seize full administrative control of storage infrastructure; four more critical CSM flaws were also patched. Dell urges upgrading to version 1.18.0 or later.
- CVE-2026-63688 exposes admin credentials for all registered storage arrays
- CVE-2026-63692 bypasses authentication in the authorization proxy and tenant service
- Four more critical CSM flaws patched, including root access on cluster nodes
- Dell recommends upgrading to CSM 1.18.0 or later
Read next
Security