Back to Newsroom
Threat Intel

Dell Fixes Critical Flaws That Let Attackers Seize Kubernetes Storage Infrastructure

Two maximum-severity bugs in Dell's Container Storage Modules could let unauthenticated attackers hijack the storage backends tied to Kubernetes — part of a batch of six critical fixes admins should apply now.

Dell Fixes Critical Flaws That Let Attackers Seize Kubernetes Storage Infrastructure

What happened

Dell has patched two maximum-severity vulnerabilities in its Container Storage Modules (CSM) — the component that connects Dell's primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT) to Kubernetes environments through the standard Container Storage Interface.

Both flaws sit in the CSM Authorization module and trace back to missing authentication checks on functions that should have required them. The first, CVE-2026-63688, lets an unauthenticated remote attacker retrieve the admin credentials for every storage array registered behind the module and bypass authorization entirely, handing over full administrative control of the storage backend. The second, CVE-2026-63692, lives in the authorization proxy and tenant service and lets an attacker skip authentication to gain admin rights there too, with the potential to reach storage resources across every tenant on a shared cluster.

Dell patched four more critical CSM issues the same day: a path to root on cluster nodes without prior privileges (CVE-2026-67269), forged authentication tokens against the CSM Authorization proxy (CVE-2026-54472), a Kubernetes access-control bypass that escalates to admin rights (CVE-2026-61421), and cluster-wide read access to Kubernetes Secrets (CVE-2026-67273).

Dell says it is not currently aware of any of the six flaws being exploited, and recommends upgrading Container Storage Modules to version 1.18.0 or later, where all six are fixed.

Why it matters

CSM sits at a sensitive trust boundary: it gives a Kubernetes cluster programmatic control over enterprise storage hardware. An authentication bypass at that layer doesn't just expose one workload, it can expose every array and every tenant the module manages — the "across all tenants" blast radius Dell itself flags for CVE-2026-63692. Read access to Kubernetes Secrets (CVE-2026-67273) raises the stakes further, since Secrets routinely hold the credentials other services trust.

Dell storage and driver components have a track record of being targeted once a patch ships and reverse-engineering begins. North Korea's Lazarus group previously abused an access-control flaw in the Dell dbutil driver to plant a Windows rootkit, and a suspected Chinese state-backed group tracked as UNC6201 — which researchers have linked to the Silk Typhoon espionage cluster — exploited a hardcoded-credential bug in Dell RecoverPoint for Virtual Machines for more than a year before it surfaced, deploying malware and hidden network interfaces on VMware ESXi hosts. CISA ordered federal agencies to patch that flaw within three days of disclosure.

What to do

  • Inventory every Dell CSM deployment across PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT clusters, and upgrade to CSM 1.18.0 or later.
  • Until patched, treat the CSM Authorization service and its network path as high-risk: restrict access to the smallest possible set of cluster components and avoid exposing it beyond the cluster network.
  • Rotate storage backend admin credentials after patching — CVE-2026-63688 allowed credential disclosure, so a leaked set survives the patch unless rotated.
  • Audit which Kubernetes Secrets are reachable by CSM-related service accounts and tighten RBAC so a compromised CSM component can't read cluster-wide Secrets.
  • Watch logs for anomalous admin-level activity against storage arrays and the CSM Authorization proxy, given the track record of state-linked actors weaponizing Dell storage and driver flaws well after disclosure.
SHARE