Dell has issued a critical alert urging administrators to patch two maximum-severity vulnerabilities in its Container Storage Modules (CSM) as soon as possible. The flaws, tracked as CVE-2026-63688 and CVE-2026-63692, allow unauthenticated attackers to gain full administrative control over storage infrastructure, making them a top priority for immediate attention.
The affected CSMs support Dell’s primary storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. These modules extend the capabilities of standard Container Storage Interface (CSI) drivers for Kubernetes environments, which are widely used in enterprise settings. The critical security flaws were discovered in the Dell CSM Authorization module due to missing authentication for critical functions.
The first vulnerability, CVE-2026-63688, enables attackers to access storage backend administrator credentials for all registered storage arrays, effectively bypassing authorization controls. This allows unauthenticated threat actors to gain complete administrative control over the storage infrastructure, potentially leading to unauthorized access and manipulation of resources across all tenants.
The second flaw, CVE-2026-63692, affects the authorization proxy and tenant service, allowing attackers to bypass authentication controls and gain admin privileges. Dell warned that this vulnerability is critical as it enables unauthenticated attackers to gain complete administrative control over the authorization service.
In addition to these two maximum-severity vulnerabilities, Dell has also patched four more critical-severity security issues in its CSMs. These include flaws that allow remote attackers to exploit without privileges, gain root access on cluster nodes, forge authentication tokens, and bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets.
Dell is advising customers to update their container storage modules to version 1.18.0 or later as soon as possible to patch these critical vulnerabilities. This is not the first time that Dell has been hit by critical security issues – state-sponsored hackers have exploited other Dell vulnerabilities in recent years, including those used in attacks by North Korean and Chinese groups.
As a result of this latest alert, administrators are urged to prioritize patching these CSM flaws without delay. With the potential for unauthenticated attackers to gain full control over storage infrastructure, it’s essential that organizations take immediate action to protect their data and systems from potential exploitation.
Source: Bleeping Computer — 2026-10-02