Critical Flaws in Dell Container Storage Modules Grant Admin Access, Full Control
**Dell** has issued patches for multiple high-severity vulnerabilities in its **Container Storage Modules (CSM)**, which are crucial for connecting Dell enterprise storage arrays to **Kubernetes** environments. These flaws, particularly two maximum-severity issues, could allow unauthenticated remote attackers to gain full administrative control over storage infrastructure and bypass authentication. IT security professionals are urged to update their systems immediately.
Dell's **Container Storage Modules (CSM)**, which integrate **Dell** storage platforms like **PowerStore**, **PowerScale**, and **PowerMax** with **Kubernetes**, have been found to contain several critical vulnerabilities. These modules extend the capabilities of standard **Container Storage Interface (CSI)** drivers, making their security paramount for enterprise environments.

### Maximum Severity Flaws Uncovered
In a recent security advisory, Dell detailed two maximum-severity flaws within the **Dell CSM Authorization** security module, both stemming from "missing authentication for critical functions" weaknesses:
* **CVE-2026-63688**: This vulnerability enables unauthenticated remote attackers to access administrator credentials for all registered storage arrays. Successful exploitation allows for a complete bypass of authorization, leading to full administrative control over the storage infrastructure.
* **CVE-2026-63692**: Found in the authorization proxy and tenant service, this flaw also permits threat actors to gain administrative privileges by circumventing authentication controls. Dell emphasized the severity, stating, "This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants."
### Additional Critical Vulnerabilities
Beyond these two, Dell also patched four other critical **CSM** security issues that can be exploited remotely without privileges:
* **CVE-2026-67269**: Allows attackers to gain root access on cluster nodes.
* **CVE-2026-54472**: Provides administrative access to the **CSM Authorization** proxy.
* **CVE-2026-61421**: Enables the forging of authentication tokens to gain administrative privileges.
* **CVE-2026-67273**: Facilitates the bypass of **Kubernetes** access controls, granting cluster-wide read access to **Kubernetes Secrets**.
Dell strongly recommends that customers upgrade their container storage modules to version **1.18.0** or later to mitigate these critical risks.
### History of Exploited Dell Vulnerabilities
While these latest vulnerabilities have not yet been flagged as actively exploited, Dell products have been targets for state-sponsored threat actors in the past. For instance:
* The North Korean **Lazarus Group** exploited **CVE-2021-21551**, an insufficient access control vulnerability in the **Dell dbutil** driver, to deploy a Windows rootkit on victim systems.
* More recently, in February, **Mandiant** and **Google Threat Intelligence Group (GTIG)** revealed that a suspected Chinese state-backed hacking group, **UNC6201**, had been exploiting **CVE-2026-22769** since mid-2024. This maximum-severity hardcoded-credential vulnerability in **Dell RecoverPoint for Virtual Machines** was used to deploy malware and create hidden network interfaces on **VMware ESXi** servers. **UNC6201** has also been linked to the **Silk Typhoon** Chinese cyberespionage group, known for targeting government agencies and deploying custom malware like **Spawnant** and **Zipline** in **Ivanti** zero-day attacks.
Following these discoveries, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** ordered federal agencies to patch vulnerable Dell systems on their networks within three days.